rendered paste body[2011/05/10 19:28:56.244037, 3, pid=3530] param/loadparm.c:9169(lp_load_ex)
lp_load_ex: refreshing parameters
Initialising global parameters
rlimit_max: rlimit_max (1024) below minimum Windows limit (16384)
[2011/05/10 19:28:56.244099, 3] ../lib/util/params.c:550(pm_process)
params.c:pm_process() - Processing configuration file "/etc/samba/smb.conf"
[2011/05/10 19:28:56.244124, 3] param/loadparm.c:7853(do_section)
Processing section "[global]"
doing parameter security = ADS
doing parameter workgroup = TESTER
doing parameter realm = child.root.PRI
doing parameter machine password timeout = 0
doing parameter log level = 10
[2011/05/10 19:28:56.244173, 5] lib/debug.c:405(debug_dump_status)
INFO: Current debug levels:
all: True/10
tdb: False/0
printdrivers: False/0
lanman: False/0
smb: False/0
rpc_parse: False/0
rpc_srv: False/0
rpc_cli: False/0
passdb: False/0
sam: False/0
auth: False/0
winbind: False/0
vfs: False/0
idmap: False/0
quota: False/0
acls: False/0
locking: False/0
msdfs: False/0
dmapi: False/0
registry: False/0
doing parameter debug pid = true
doing parameter log file = /var/log/samba/smbd.log
[2011/05/10 19:28:56.244270, 2, pid=3530] param/loadparm.c:7870(do_section)
Processing section "[testshare]"
[2011/05/10 19:28:56.244302, 8, pid=3530] param/loadparm.c:6174(add_a_service)
add_a_service: Creating snum = 0 for testshare
[2011/05/10 19:28:56.244315, 10, pid=3530] param/loadparm.c:6212(hash_a_service)
hash_a_service: creating servicehash
[2011/05/10 19:28:56.244331, 10, pid=3530] param/loadparm.c:6221(hash_a_service)
hash_a_service: hashing index 0 for service name testshare
doing parameter comment = This is a test share
doing parameter path = /share
doing parameter browseable = yes
doing parameter read only = no
doing parameter valid users = useraccount
doing parameter writeable = yes
doing parameter guest ok = yes
[2011/05/10 19:28:56.244424, 4, pid=3530] param/loadparm.c:9204(lp_load_ex)
pm_process() returned Yes
[2011/05/10 19:28:56.244444, 7, pid=3530] param/loadparm.c:9410(lp_servicenumber)
lp_servicenumber: couldn't find homes
[2011/05/10 19:28:56.244469, 8, pid=3530] param/loadparm.c:6174(add_a_service)
add_a_service: Creating snum = 1 for IPC$
[2011/05/10 19:28:56.244480, 10, pid=3530] param/loadparm.c:6221(hash_a_service)
hash_a_service: hashing index 1 for service name IPC$
[2011/05/10 19:28:56.244501, 3, pid=3530] param/loadparm.c:6324(lp_add_ipc)
adding IPC service
[2011/05/10 19:28:56.244513, 10, pid=3530] param/loadparm.c:8414(set_server_role)
set_server_role: role = ROLE_DOMAIN_MEMBER
[2011/05/10 19:28:56.244531, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244550, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244581, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244597, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244613, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244627, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244642, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244657, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244673, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244688, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244704, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244721, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244768, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244806, 5, pid=3530] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.244820, 7, pid=3530] param/loadparm.c:9410(lp_servicenumber)
lp_servicenumber: couldn't find printers
[2011/05/10 19:28:56.244836, 3, pid=3530] printing/pcap.c:136(pcap_cache_reload)
reloading printcap cache
[2011/05/10 19:28:56.244858, 5, pid=3530] printing/print_cups.c:408(cups_pcap_load_async)
cups_pcap_load_async: asynchronously loading cups printers
[2011/05/10 19:28:56.247313, 5, pid=3531] printing/print_cups.c:169(cups_cache_reload_async)
reloading cups printcap cache
[2011/05/10 19:28:56.248926, 10, pid=3531] printing/print_cups.c:87(cups_connect)
connecting to cups server /var/run/cups/cups.sock:631
[2011/05/10 19:28:56.255368, 10, pid=3530] printing/print_cups.c:425(cups_pcap_load_async)
cups_pcap_load_async: child pid = 3531
[2011/05/10 19:28:56.255446, 10, pid=3530] printing/print_cups.c:576(cups_cache_reload)
cups_cache_reload: sync read on fd 4
[2011/05/10 19:28:56.255463, 5, pid=3530] printing/print_cups.c:458(cups_async_callback)
cups_async_callback: callback received for printer data. fd = 4
[2011/05/10 19:28:56.255478, 2, pid=3530] printing/print_cups.c:550(cups_async_callback)
cups_async_callback: failed to read a new printer list
[2011/05/10 19:28:56.255500, 3, pid=3530] printing/pcap.c:243(pcap_cache_reload)
reload status: error
[2011/05/10 19:28:56.255529, 3, pid=3530] printing/pcap.c:136(pcap_cache_reload)
reloading printcap cache
[2011/05/10 19:28:56.255542, 5, pid=3530] printing/print_cups.c:408(cups_pcap_load_async)
cups_pcap_load_async: asynchronously loading cups printers
[2011/05/10 19:28:56.257802, 5, pid=3532] printing/print_cups.c:169(cups_cache_reload_async)
reloading cups printcap cache
[2011/05/10 19:28:56.259258, 10, pid=3532] printing/print_cups.c:87(cups_connect)
connecting to cups server /var/run/cups/cups.sock:631
[2011/05/10 19:28:56.264001, 10, pid=3530] printing/print_cups.c:425(cups_pcap_load_async)
cups_pcap_load_async: child pid = 3532
[2011/05/10 19:28:56.264061, 10, pid=3530] printing/print_cups.c:576(cups_cache_reload)
cups_cache_reload: sync read on fd 4
[2011/05/10 19:28:56.264074, 5, pid=3530] printing/print_cups.c:458(cups_async_callback)
cups_async_callback: callback received for printer data. fd = 4
[2011/05/10 19:28:56.264087, 2, pid=3530] printing/print_cups.c:550(cups_async_callback)
cups_async_callback: failed to read a new printer list
[2011/05/10 19:28:56.264109, 3, pid=3530] printing/pcap.c:243(pcap_cache_reload)
reload status: error
[2011/05/10 19:28:56.264136, 7, pid=3530] param/loadparm.c:9410(lp_servicenumber)
lp_servicenumber: couldn't find printers
[2011/05/10 19:28:56.264159, 7, pid=3530] param/loadparm.c:9410(lp_servicenumber)
lp_servicenumber: couldn't find printers
[2011/05/10 19:28:56.264182, 6, pid=3530] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:28:56.264494, 2, pid=3530] lib/interface.c:340(add_interface)
added interface eth0 ip=fe80::250:56ff:fea8:58ff%eth0 bcast=fe80::ffff:ffff:ffff:ffff%eth0 netmask=ffff:ffff:ffff:ffff::
[2011/05/10 19:28:56.264616, 2, pid=3530] lib/interface.c:340(add_interface)
added interface eth0 ip=10.215.3.27 bcast=10.215.255.255 netmask=255.255.0.0
[2011/05/10 19:28:56.264691, 5, pid=3530] lib/util.c:276(init_names)
Netbios name list:-
my_netbios_names[0]="NPSMTP000"
[2011/05/10 19:28:56.264799, 3, pid=3530] smbd/server.c:1161(main)
loaded services
[2011/05/10 19:28:56.264813, 3, pid=3530] smbd/server.c:1176(main)
Becoming a daemon.
[2011/05/10 19:28:56.267091, 8, pid=3533] ../lib/util/util.c:217(fcntl_lock)
fcntl_lock 9 6 0 1 1
[2011/05/10 19:28:56.267241, 8, pid=3533] ../lib/util/util.c:252(fcntl_lock)
fcntl_lock: Lock call successful
[2011/05/10 19:28:56.267625, 5, pid=3533] passdb/pdb_interface.c:63(smb_register_passdb)
Attempting to register passdb backend ldapsam
[2011/05/10 19:28:56.267660, 5, pid=3533] passdb/pdb_interface.c:76(smb_register_passdb)
Successfully added passdb backend 'ldapsam'
[2011/05/10 19:28:56.267672, 5, pid=3533] passdb/pdb_interface.c:63(smb_register_passdb)
Attempting to register passdb backend ldapsam_compat
[2011/05/10 19:28:56.267683, 5, pid=3533] passdb/pdb_interface.c:76(smb_register_passdb)
Successfully added passdb backend 'ldapsam_compat'
[2011/05/10 19:28:56.267698, 5, pid=3533] passdb/pdb_interface.c:63(smb_register_passdb)
Attempting to register passdb backend NDS_ldapsam
[2011/05/10 19:28:56.267710, 5, pid=3533] passdb/pdb_interface.c:76(smb_register_passdb)
Successfully added passdb backend 'NDS_ldapsam'
[2011/05/10 19:28:56.267721, 5, pid=3533] passdb/pdb_interface.c:63(smb_register_passdb)
Attempting to register passdb backend NDS_ldapsam_compat
[2011/05/10 19:28:56.267731, 5, pid=3533] passdb/pdb_interface.c:76(smb_register_passdb)
Successfully added passdb backend 'NDS_ldapsam_compat'
[2011/05/10 19:28:56.267746, 5, pid=3533] passdb/pdb_interface.c:63(smb_register_passdb)
Attempting to register passdb backend smbpasswd
[2011/05/10 19:28:56.267758, 5, pid=3533] passdb/pdb_interface.c:76(smb_register_passdb)
Successfully added passdb backend 'smbpasswd'
[2011/05/10 19:28:56.267772, 5, pid=3533] passdb/pdb_interface.c:63(smb_register_passdb)
Attempting to register passdb backend tdbsam
[2011/05/10 19:28:56.267784, 5, pid=3533] passdb/pdb_interface.c:76(smb_register_passdb)
Successfully added passdb backend 'tdbsam'
[2011/05/10 19:28:56.267798, 5, pid=3533] passdb/pdb_interface.c:63(smb_register_passdb)
Attempting to register passdb backend wbc_sam
[2011/05/10 19:28:56.267816, 5, pid=3533] passdb/pdb_interface.c:76(smb_register_passdb)
Successfully added passdb backend 'wbc_sam'
[2011/05/10 19:28:56.267827, 5, pid=3533] passdb/pdb_interface.c:133(make_pdb_method_name)
Attempting to find a passdb backend to match tdbsam (tdbsam)
[2011/05/10 19:28:56.267843, 5, pid=3533] passdb/pdb_interface.c:154(make_pdb_method_name)
Found pdb backend tdbsam
[2011/05/10 19:28:56.267884, 5, pid=3533] passdb/pdb_interface.c:165(make_pdb_method_name)
pdb backend tdbsam has a valid init
[2011/05/10 19:28:56.268505, 5, pid=3533] libsmb/namecache.c:51(namecache_enable)
namecache_enable: enabling netbios namecache, timeout 660 seconds
[2011/05/10 19:28:56.268625, 10, pid=3533] registry/reg_cachehook.c:73(reghook_cache_init)
reghook_cache_init: new tree with default ops 0x2b678dc89600 for key []
[2011/05/10 19:28:56.268833, 10, pid=3533] registry/reg_backend_db.c:1620(regdb_fetch_values_internal)
regdb_fetch_values: Looking for value of key [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports]
[2011/05/10 19:28:56.268878, 8, pid=3533] registry/reg_backend_db.c:1567(regdb_unpack_values)
specific: [Samba Printer Port], len: 2
[2011/05/10 19:28:56.268897, 10, pid=3533] registry/reg_backend_db.c:1620(regdb_fetch_values_internal)
regdb_fetch_values: Looking for value of key [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers]
[2011/05/10 19:28:56.268923, 8, pid=3533] registry/reg_backend_db.c:1567(regdb_unpack_values)
specific: [DefaultSpoolDirectory], len: 70
[2011/05/10 19:28:56.268939, 10, pid=3533] registry/reg_backend_db.c:1620(regdb_fetch_values_internal)
regdb_fetch_values: Looking for value of key [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog]
[2011/05/10 19:28:56.268962, 8, pid=3533] registry/reg_backend_db.c:1567(regdb_unpack_values)
specific: [DisplayName], len: 20
[2011/05/10 19:28:56.268988, 8, pid=3533] registry/reg_backend_db.c:1567(regdb_unpack_values)
specific: [ErrorControl], len: 4
[2011/05/10 19:28:56.269006, 10, pid=3533] registry/reg_backend_db.c:1620(regdb_fetch_values_internal)
regdb_fetch_values: Looking for value of key [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog]
[2011/05/10 19:28:56.269030, 8, pid=3533] registry/reg_backend_db.c:1567(regdb_unpack_values)
specific: [DisplayName], len: 20
[2011/05/10 19:28:56.269049, 8, pid=3533] registry/reg_backend_db.c:1567(regdb_unpack_values)
specific: [ErrorControl], len: 4
[2011/05/10 19:28:56.269069, 10, pid=3533] registry/reg_cachehook.c:97(reghook_cache_add)
reghook_cache_add: Adding ops 0x2b678dc898a0 for key [/HKLM/SYSTEM/CurrentControlSet/Control/Print]
[2011/05/10 19:28:56.269082, 8, pid=3533] lib/adt_tree.c:200(pathtree_add)
pathtree_add: Enter
[2011/05/10 19:28:56.269100, 10, pid=3533] lib/adt_tree.c:267(pathtree_add)
pathtree_add: Successfully added node [HKLM/SYSTEM/CurrentControlSet/Control/Print] to tree
[2011/05/10 19:28:56.269111, 8, pid=3533] lib/adt_tree.c:269(pathtree_add)
pathtree_add: Exit
[2011/05/10 19:28:56.269123, 10, pid=3533] registry/reg_cachehook.c:97(reghook_cache_add)
reghook_cache_add: Adding ops 0x2b678dc898a0 for key [/HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Print/Printers]
[2011/05/10 19:28:56.269134, 8, pid=3533] lib/adt_tree.c:200(pathtree_add)
pathtree_add: Enter
[2011/05/10 19:28:56.269147, 10, pid=3533] lib/adt_tree.c:267(pathtree_add)
pathtree_add: Successfully added node [HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Print/Printers] to tree
[2011/05/10 19:28:56.269158, 8, pid=3533] lib/adt_tree.c:269(pathtree_add)
pathtree_add: Exit
[2011/05/10 19:28:56.269170, 10, pid=3533] registry/reg_cachehook.c:97(reghook_cache_add)
reghook_cache_add: Adding ops 0x2b678dc898a0 for key [/HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Ports]
[2011/05/10 19:28:56.269181, 8, pid=3533] lib/adt_tree.c:200(pathtree_add)
pathtree_add: Enter
[2011/05/10 19:28:56.269192, 10, pid=3533] lib/adt_tree.c:267(pathtree_add)
pathtree_add: Successfully added node [HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Ports] to tree
[2011/05/10 19:28:56.269203, 8, pid=3533] lib/adt_tree.c:269(pathtree_add)
pathtree_add: Exit
[2011/05/10 19:28:56.269214, 10, pid=3533] registry/reg_cachehook.c:97(reghook_cache_add)
reghook_cache_add: Adding ops 0x2b678dc89900 for key [/HKLM/SYSTEM/CurrentControlSet/Services/LanmanServer/Shares]
[2011/05/10 19:28:56.269226, 8, pid=3533] lib/adt_tree.c:200(pathtree_add)
pathtree_add: Enter
[2011/05/10 19:28:56.269239, 10, pid=3533] lib/adt_tree.c:267(pathtree_add)
pathtree_add: Successfully added node [HKLM/SYSTEM/CurrentControlSet/Services/LanmanServer/Shares] to tree
[2011/05/10 19:28:56.269250, 8, pid=3533] lib/adt_tree.c:269(pathtree_add)
pathtree_add: Exit
[2011/05/10 19:28:56.269261, 10, pid=3533] registry/reg_cachehook.c:97(reghook_cache_add)
reghook_cache_add: Adding ops 0x2b678dc89700 for key [/HKLM/SOFTWARE/Samba/smbconf]
[2011/05/10 19:28:56.269283, 8, pid=3533] lib/adt_tree.c:200(pathtree_add)
pathtree_add: Enter
[2011/05/10 19:28:56.269296, 10, pid=3533] lib/adt_tree.c:267(pathtree_add)
pathtree_add: Successfully added node [HKLM/SOFTWARE/Samba/smbconf] to tree
[2011/05/10 19:28:56.269307, 8, pid=3533] lib/adt_tree.c:269(pathtree_add)
pathtree_add: Exit
[2011/05/10 19:28:56.269318, 10, pid=3533] registry/reg_cachehook.c:97(reghook_cache_add)
reghook_cache_add: Adding ops 0x2b678dc89960 for key [/HKLM/SYSTEM/CurrentControlSet/Services/Netlogon/Parameters]
[2011/05/10 19:28:56.269330, 8, pid=3533] lib/adt_tree.c:200(pathtree_add)
pathtree_add: Enter
[2011/05/10 19:28:56.269341, 10, pid=3533] lib/adt_tree.c:267(pathtree_add)
pathtree_add: Successfully added node [HKLM/SYSTEM/CurrentControlSet/Services/Netlogon/Parameters] to tree
[2011/05/10 19:28:56.269352, 8, pid=3533] lib/adt_tree.c:269(pathtree_add)
pathtree_add: Exit
[2011/05/10 19:28:56.269363, 10, pid=3533] registry/reg_cachehook.c:97(reghook_cache_add)
reghook_cache_add: Adding ops 0x2b678dc899c0 for key [/HKLM/SYSTEM/CurrentControlSet/Control/ProductOptions]
[2011/05/10 19:28:56.269374, 8, pid=3533] lib/adt_tree.c:200(pathtree_add)
pathtree_add: Enter
[2011/05/10 19:28:56.269385, 10, pid=3533] lib/adt_tree.c:267(pathtree_add)
pathtree_add: Successfully added node [HKLM/SYSTEM/CurrentControlSet/Control/ProductOptions] to tree
[2011/05/10 19:28:56.269402, 8, pid=3533] lib/adt_tree.c:269(pathtree_add)
pathtree_add: Exit
[2011/05/10 19:28:56.269415, 10, pid=3533] registry/reg_cachehook.c:97(reghook_cache_add)
reghook_cache_add: Adding ops 0x2b678dc89a20 for key [/HKLM/SYSTEM/CurrentControlSet/Services/Tcpip/Parameters]
[2011/05/10 19:28:56.269426, 8, pid=3533] lib/adt_tree.c:200(pathtree_add)
pathtree_add: Enter
[2011/05/10 19:28:56.269437, 10, pid=3533] lib/adt_tree.c:267(pathtree_add)
pathtree_add: Successfully added node [HKLM/SYSTEM/CurrentControlSet/Services/Tcpip/Parameters] to tree
[2011/05/10 19:28:56.269448, 8, pid=3533] lib/adt_tree.c:269(pathtree_add)
pathtree_add: Exit
[2011/05/10 19:28:56.269459, 10, pid=3533] registry/reg_cachehook.c:97(reghook_cache_add)
reghook_cache_add: Adding ops 0x2b678dc89a80 for key [/HKPT]
[2011/05/10 19:28:56.269469, 8, pid=3533] lib/adt_tree.c:200(pathtree_add)
pathtree_add: Enter
[2011/05/10 19:28:56.269480, 10, pid=3533] lib/adt_tree.c:267(pathtree_add)
pathtree_add: Successfully added node [HKPT] to tree
[2011/05/10 19:28:56.269490, 8, pid=3533] lib/adt_tree.c:269(pathtree_add)
pathtree_add: Exit
[2011/05/10 19:28:56.269507, 10, pid=3533] registry/reg_cachehook.c:97(reghook_cache_add)
reghook_cache_add: Adding ops 0x2b678dc89ae0 for key [/HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion]
[2011/05/10 19:28:56.269520, 8, pid=3533] lib/adt_tree.c:200(pathtree_add)
pathtree_add: Enter
[2011/05/10 19:28:56.269531, 10, pid=3533] lib/adt_tree.c:267(pathtree_add)
pathtree_add: Successfully added node [HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion] to tree
[2011/05/10 19:28:56.269541, 8, pid=3533] lib/adt_tree.c:269(pathtree_add)
pathtree_add: Exit
[2011/05/10 19:28:56.269552, 10, pid=3533] registry/reg_cachehook.c:97(reghook_cache_add)
reghook_cache_add: Adding ops 0x2b678dc89b40 for key [/HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Perflib]
[2011/05/10 19:28:56.269564, 8, pid=3533] lib/adt_tree.c:200(pathtree_add)
pathtree_add: Enter
[2011/05/10 19:28:56.269575, 10, pid=3533] lib/adt_tree.c:267(pathtree_add)
pathtree_add: Successfully added node [HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Perflib] to tree
[2011/05/10 19:28:56.269586, 8, pid=3533] lib/adt_tree.c:269(pathtree_add)
pathtree_add: Exit
[2011/05/10 19:28:56.270726, 5, pid=3533] lib/gencache.c:65(gencache_init)
Opening cache file at /var/lib/samba/gencache.tdb
[2011/05/10 19:28:56.270809, 5, pid=3533] lib/gencache.c:108(gencache_init)
Opening cache file at /var/lib/samba/gencache_notrans.tdb
[2011/05/10 19:28:56.270886, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = IDMAP/UID2SID/0 couldn't be found
[2011/05/10 19:28:56.272011, 5, pid=3533] passdb/lookup_sid.c:1334(uid_to_sid)
uid_to_sid: winbind failed to find a sid for uid 0
[2011/05/10 19:28:56.272071, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.272092, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.272110, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.272126, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.272139, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.272231, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 2
[2011/05/10 19:28:56.272245, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 1
[2011/05/10 19:28:56.272255, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 2
[2011/05/10 19:28:56.272266, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.272276, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.272389, 4, pid=3533] passdb/pdb_tdb.c:518(tdbsam_open)
tdbsam_open: successfully opened /var/lib/samba/private/passdb.tdb
[2011/05/10 19:28:56.272406, 5, pid=3533] passdb/pdb_tdb.c:557(tdbsam_getsampwnam)
pdb_getsampwnam (TDB): error fetching database.
Key: USER_root
[2011/05/10 19:28:56.272424, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.272435, 5, pid=3533] passdb/pdb_interface.c:1214(pdb_default_uid_to_sid)
pdb_default_uid_to_sid: Did not find user root (0)
[2011/05/10 19:28:56.272450, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.272473, 10, pid=3533] passdb/lookup_sid.c:1151(legacy_uid_to_sid)
LEGACY: uid 0 -> sid S-1-22-1-0
[2011/05/10 19:28:56.272516, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = IDMAP/GID2SID/0 couldn't be found
[2011/05/10 19:28:56.272701, 5, pid=3533] passdb/lookup_sid.c:1387(gid_to_sid)
gid_to_sid: winbind failed to find a sid for gid 0
[2011/05/10 19:28:56.272716, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.272728, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.272739, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.272749, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.272759, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.273179, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.273199, 10, pid=3533] passdb/lookup_sid.c:1182(legacy_gid_to_sid)
LEGACY: gid 0 -> sid S-1-22-2-0
[2011/05/10 19:28:56.273216, 10, pid=3533] auth/token_util.c:356(create_local_nt_token)
Create local NT token for S-1-22-1-0
[2011/05/10 19:28:56.273245, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = IDMAP/SID2GID/S-1-5-32-544 couldn't be found
[2011/05/10 19:28:56.273523, 10, pid=3533] passdb/lookup_sid.c:1511(sid_to_gid)
winbind failed to find a gid for sid S-1-5-32-544
[2011/05/10 19:28:56.273542, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.273555, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.273566, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.273577, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.273588, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.273659, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.273672, 10, pid=3533] passdb/lookup_sid.c:1256(legacy_sid_to_gid)
LEGACY: mapping failed for sid S-1-5-32-544
[2011/05/10 19:28:56.273684, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.273695, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.273705, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.273715, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.273725, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.273748, 3, pid=3533] auth/token_util.c:436(create_local_nt_token)
Failed to fetch domain sid for TESTER
[2011/05/10 19:28:56.273762, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.273805, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = IDMAP/SID2GID/S-1-5-32-545 couldn't be found
[2011/05/10 19:28:56.273991, 10, pid=3533] passdb/lookup_sid.c:1511(sid_to_gid)
winbind failed to find a gid for sid S-1-5-32-545
[2011/05/10 19:28:56.274007, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.274018, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.274029, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.274039, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.274049, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.274097, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.274110, 10, pid=3533] passdb/lookup_sid.c:1256(legacy_sid_to_gid)
LEGACY: mapping failed for sid S-1-5-32-545
[2011/05/10 19:28:56.274122, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.274133, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.274143, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.274153, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.274162, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.274183, 3, pid=3533] auth/token_util.c:467(create_local_nt_token)
Failed to fetch domain sid for TESTER
[2011/05/10 19:28:56.274196, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.274208, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.274219, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.274228, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.274238, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.274249, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.274407, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.274496, 3, pid=3533] lib/privileges.c:63(get_privileges)
get_privileges: No privileges assigned to SID [S-1-22-1-0]
[2011/05/10 19:28:56.274515, 5, pid=3533] lib/privileges.c:128(get_privileges_for_sids)
get_privileges_for_sids: sid = S-1-5-32-544
Privilege set:
SE_PRIV 0xff0 0x0 0x0 0x0
[2011/05/10 19:28:56.274549, 5, pid=3533] lib/privileges.c:128(get_privileges_for_sids)
get_privileges_for_sids: sid = S-1-1-0
Privilege set:
SE_PRIV 0x0 0x0 0x0 0x0
[2011/05/10 19:28:56.274571, 3, pid=3533] lib/privileges.c:63(get_privileges)
get_privileges: No privileges assigned to SID [S-1-5-2]
[2011/05/10 19:28:56.274586, 3, pid=3533] lib/privileges.c:63(get_privileges)
get_privileges: No privileges assigned to SID [S-1-5-11]
[2011/05/10 19:28:56.274608, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [HKLM]
[2011/05/10 19:28:56.274626, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (1)
[2011/05/10 19:28:56.274641, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM]
[2011/05/10 19:28:56.274658, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM]
[2011/05/10 19:28:56.274670, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.274680, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM]
[2011/05/10 19:28:56.274733, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM]
[2011/05/10 19:28:56.274772, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [SYSTEM]
[2011/05/10 19:28:56.274785, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (2)
[2011/05/10 19:28:56.274797, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM]
[2011/05/10 19:28:56.274807, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM]
[2011/05/10 19:28:56.274818, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.274827, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM]
[2011/05/10 19:28:56.274856, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM]
[2011/05/10 19:28:56.274878, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [CurrentControlSet]
[2011/05/10 19:28:56.274890, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (3)
[2011/05/10 19:28:56.274902, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.274912, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.274923, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.274932, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.274956, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet]
[2011/05/10 19:28:56.275016, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (3)
[2011/05/10 19:28:56.275030, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Services]
[2011/05/10 19:28:56.275041, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (3)
[2011/05/10 19:28:56.275054, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.275064, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.275076, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.275085, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.275121, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services]
[2011/05/10 19:28:56.275143, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (3)
[2011/05/10 19:28:56.275155, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (2)
[2011/05/10 19:28:56.275231, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [HKLM]
[2011/05/10 19:28:56.275245, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (2)
[2011/05/10 19:28:56.275265, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM]
[2011/05/10 19:28:56.275275, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM]
[2011/05/10 19:28:56.275286, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.275306, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM]
[2011/05/10 19:28:56.275331, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM]
[2011/05/10 19:28:56.275351, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [SYSTEM]
[2011/05/10 19:28:56.275363, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (3)
[2011/05/10 19:28:56.275375, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM]
[2011/05/10 19:28:56.275386, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM]
[2011/05/10 19:28:56.275396, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.275405, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM]
[2011/05/10 19:28:56.275434, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM]
[2011/05/10 19:28:56.275456, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [CurrentControlSet]
[2011/05/10 19:28:56.275468, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.275480, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.275490, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.275500, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.275509, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.275532, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet]
[2011/05/10 19:28:56.275553, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.275565, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Services]
[2011/05/10 19:28:56.275576, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.275588, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.275599, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.275609, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.275627, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.275658, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services]
[2011/05/10 19:28:56.275681, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.275693, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Spooler]
[2011/05/10 19:28:56.275704, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.275724, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services/Spooler]
[2011/05/10 19:28:56.275735, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services/Spooler]
[2011/05/10 19:28:56.275746, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.275756, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services/Spooler]
[2011/05/10 19:28:56.275780, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\Spooler]
[2011/05/10 19:28:56.275802, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.275814, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (3)
[2011/05/10 19:28:56.275977, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276005, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276027, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276047, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276063, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276078, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276092, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276107, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276125, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276141, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276162, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276215, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276236, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276257, 5, pid=3533] lib/charcnv.c:98(charset_name)
Substituting charset 'UTF-8' for LOCALE
[2011/05/10 19:28:56.276313, 10, pid=3533] registry/reg_backend_db.c:1663(regdb_store_values_internal)
regdb_store_values: Looking for value of key [HKLM\SYSTEM\CurrentControlSet\Services\Spooler]
[2011/05/10 19:28:56.276344, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (2)
[2011/05/10 19:28:56.276358, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [HKLM]
[2011/05/10 19:28:56.276370, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (2)
[2011/05/10 19:28:56.276383, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM]
[2011/05/10 19:28:56.276394, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM]
[2011/05/10 19:28:56.276404, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.276415, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM]
[2011/05/10 19:28:56.276438, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM]
[2011/05/10 19:28:56.276459, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [SYSTEM]
[2011/05/10 19:28:56.276480, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (3)
[2011/05/10 19:28:56.276492, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM]
[2011/05/10 19:28:56.276502, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM]
[2011/05/10 19:28:56.276512, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.276521, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM]
[2011/05/10 19:28:56.276542, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM]
[2011/05/10 19:28:56.276563, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [CurrentControlSet]
[2011/05/10 19:28:56.276574, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.276587, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.276597, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.276607, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.276616, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.276639, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet]
[2011/05/10 19:28:56.276661, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.276672, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Services]
[2011/05/10 19:28:56.276684, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.276696, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.276706, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.276717, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.276727, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.276765, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services]
[2011/05/10 19:28:56.276789, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.276801, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Spooler]
[2011/05/10 19:28:56.276813, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.276825, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services/Spooler]
[2011/05/10 19:28:56.276836, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services/Spooler]
[2011/05/10 19:28:56.276846, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.276856, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services/Spooler]
[2011/05/10 19:28:56.276880, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\Spooler]
[2011/05/10 19:28:56.276910, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.276921, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Security]
[2011/05/10 19:28:56.276932, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.276945, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services/Spooler/Security]
[2011/05/10 19:28:56.276956, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services/Spooler/Security]
[2011/05/10 19:28:56.276977, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.276988, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services/Spooler/Security]
[2011/05/10 19:28:56.277011, 10, pid=3533] registry/reg_backend_db.c:1483(regdb_fetch_keys_internal)
regdb_fetch_keys: no subkeys found for key [HKLM\SYSTEM\CurrentControlSet\Services\Spooler\Security]
[2011/05/10 19:28:56.277023, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\Spooler\Security]
[2011/05/10 19:28:56.277052, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.277065, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (3)
[2011/05/10 19:28:56.277096, 10, pid=3533] registry/reg_backend_db.c:1663(regdb_store_values_internal)
regdb_store_values: Looking for value of key [HKLM\SYSTEM\CurrentControlSet\Services\Spooler\Security]
[2011/05/10 19:28:56.277122, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (2)
[2011/05/10 19:28:56.277163, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [HKLM]
[2011/05/10 19:28:56.277175, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (2)
[2011/05/10 19:28:56.277188, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM]
[2011/05/10 19:28:56.277198, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM]
[2011/05/10 19:28:56.277208, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.277218, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM]
[2011/05/10 19:28:56.277240, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM]
[2011/05/10 19:28:56.277261, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [SYSTEM]
[2011/05/10 19:28:56.277273, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (3)
[2011/05/10 19:28:56.277285, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM]
[2011/05/10 19:28:56.277295, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM]
[2011/05/10 19:28:56.277319, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.277329, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM]
[2011/05/10 19:28:56.277351, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM]
[2011/05/10 19:28:56.277373, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [CurrentControlSet]
[2011/05/10 19:28:56.277397, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.277411, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.277421, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.277431, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.277441, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.277472, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet]
[2011/05/10 19:28:56.277495, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.277506, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Services]
[2011/05/10 19:28:56.277517, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.277530, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.277540, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.277550, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.277560, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.277590, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services]
[2011/05/10 19:28:56.277613, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.277624, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [NETLOGON]
[2011/05/10 19:28:56.277636, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.277648, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services/NETLOGON]
[2011/05/10 19:28:56.277658, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services/NETLOGON]
[2011/05/10 19:28:56.277669, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.277678, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services/NETLOGON]
[2011/05/10 19:28:56.277705, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON]
[2011/05/10 19:28:56.277728, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.277739, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (3)
[2011/05/10 19:28:56.277816, 10, pid=3533] registry/reg_backend_db.c:1663(regdb_store_values_internal)
regdb_store_values: Looking for value of key [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON]
[2011/05/10 19:28:56.277845, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (2)
[2011/05/10 19:28:56.277867, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [HKLM]
[2011/05/10 19:28:56.277879, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (2)
[2011/05/10 19:28:56.277899, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM]
[2011/05/10 19:28:56.277910, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM]
[2011/05/10 19:28:56.277920, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.277930, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM]
[2011/05/10 19:28:56.277952, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM]
[2011/05/10 19:28:56.277987, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [SYSTEM]
[2011/05/10 19:28:56.278000, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (3)
[2011/05/10 19:28:56.278012, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM]
[2011/05/10 19:28:56.278022, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM]
[2011/05/10 19:28:56.278032, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.278042, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM]
[2011/05/10 19:28:56.278064, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM]
[2011/05/10 19:28:56.278086, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [CurrentControlSet]
[2011/05/10 19:28:56.278098, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.278110, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.278120, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.278130, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.278140, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.278164, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet]
[2011/05/10 19:28:56.278185, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.278197, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Services]
[2011/05/10 19:28:56.278208, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.278220, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.278230, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.278241, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.278250, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.278282, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services]
[2011/05/10 19:28:56.278315, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.278329, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [NETLOGON]
[2011/05/10 19:28:56.278340, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.278360, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services/NETLOGON]
[2011/05/10 19:28:56.278371, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services/NETLOGON]
[2011/05/10 19:28:56.278382, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.278392, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services/NETLOGON]
[2011/05/10 19:28:56.278418, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON]
[2011/05/10 19:28:56.278441, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.278453, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Security]
[2011/05/10 19:28:56.278464, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.278477, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services/NETLOGON/Security]
[2011/05/10 19:28:56.278488, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services/NETLOGON/Security]
[2011/05/10 19:28:56.278499, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.278509, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services/NETLOGON/Security]
[2011/05/10 19:28:56.278538, 10, pid=3533] registry/reg_backend_db.c:1483(regdb_fetch_keys_internal)
regdb_fetch_keys: no subkeys found for key [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON\Security]
[2011/05/10 19:28:56.278552, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON\Security]
[2011/05/10 19:28:56.278576, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.278588, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (3)
[2011/05/10 19:28:56.278607, 10, pid=3533] registry/reg_backend_db.c:1663(regdb_store_values_internal)
regdb_store_values: Looking for value of key [HKLM\SYSTEM\CurrentControlSet\Services\NETLOGON\Security]
[2011/05/10 19:28:56.278632, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (2)
[2011/05/10 19:28:56.278674, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [HKLM]
[2011/05/10 19:28:56.278687, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (2)
[2011/05/10 19:28:56.278699, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM]
[2011/05/10 19:28:56.278710, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM]
[2011/05/10 19:28:56.278721, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.278731, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM]
[2011/05/10 19:28:56.278754, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM]
[2011/05/10 19:28:56.278775, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [SYSTEM]
[2011/05/10 19:28:56.278787, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (3)
[2011/05/10 19:28:56.278799, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM]
[2011/05/10 19:28:56.278817, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM]
[2011/05/10 19:28:56.278828, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.278838, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM]
[2011/05/10 19:28:56.278861, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM]
[2011/05/10 19:28:56.278883, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [CurrentControlSet]
[2011/05/10 19:28:56.278894, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.278914, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.278926, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.278937, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.278947, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.278983, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet]
[2011/05/10 19:28:56.279007, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.279019, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Services]
[2011/05/10 19:28:56.279030, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.279043, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.279053, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.279064, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.279074, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.279113, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services]
[2011/05/10 19:28:56.279138, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.279150, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [RemoteRegistry]
[2011/05/10 19:28:56.279161, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.279175, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services/RemoteRegistry]
[2011/05/10 19:28:56.279186, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services/RemoteRegistry]
[2011/05/10 19:28:56.279197, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.279207, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services/RemoteRegistry]
[2011/05/10 19:28:56.279231, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry]
[2011/05/10 19:28:56.279254, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.279274, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (3)
[2011/05/10 19:28:56.279345, 10, pid=3533] registry/reg_backend_db.c:1663(regdb_store_values_internal)
regdb_store_values: Looking for value of key [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry]
[2011/05/10 19:28:56.279382, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (2)
[2011/05/10 19:28:56.279398, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [HKLM]
[2011/05/10 19:28:56.279409, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (2)
[2011/05/10 19:28:56.279422, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM]
[2011/05/10 19:28:56.279432, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM]
[2011/05/10 19:28:56.279442, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.279452, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM]
[2011/05/10 19:28:56.279475, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM]
[2011/05/10 19:28:56.279496, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [SYSTEM]
[2011/05/10 19:28:56.279508, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (3)
[2011/05/10 19:28:56.279520, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM]
[2011/05/10 19:28:56.279531, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM]
[2011/05/10 19:28:56.279541, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.279551, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM]
[2011/05/10 19:28:56.279573, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM]
[2011/05/10 19:28:56.279595, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [CurrentControlSet]
[2011/05/10 19:28:56.279606, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.279619, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.279629, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.279640, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.279649, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.279673, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet]
[2011/05/10 19:28:56.279695, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.279707, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Services]
[2011/05/10 19:28:56.279719, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.279732, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.279742, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.279760, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.279771, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.279803, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services]
[2011/05/10 19:28:56.279825, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.279836, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [RemoteRegistry]
[2011/05/10 19:28:56.279847, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.279860, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services/RemoteRegistry]
[2011/05/10 19:28:56.279871, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services/RemoteRegistry]
[2011/05/10 19:28:56.279882, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.279892, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services/RemoteRegistry]
[2011/05/10 19:28:56.279916, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry]
[2011/05/10 19:28:56.279938, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.279950, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Security]
[2011/05/10 19:28:56.279961, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.279986, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services/RemoteRegistry/Security]
[2011/05/10 19:28:56.279998, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services/RemoteRegistry/Security]
[2011/05/10 19:28:56.280009, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.280019, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services/RemoteRegistry/Security]
[2011/05/10 19:28:56.280041, 10, pid=3533] registry/reg_backend_db.c:1483(regdb_fetch_keys_internal)
regdb_fetch_keys: no subkeys found for key [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security]
[2011/05/10 19:28:56.280054, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security]
[2011/05/10 19:28:56.280078, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.280090, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (3)
[2011/05/10 19:28:56.280113, 10, pid=3533] registry/reg_backend_db.c:1663(regdb_store_values_internal)
regdb_store_values: Looking for value of key [HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security]
[2011/05/10 19:28:56.280139, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (2)
[2011/05/10 19:28:56.280186, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [HKLM]
[2011/05/10 19:28:56.280199, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (2)
[2011/05/10 19:28:56.280212, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM]
[2011/05/10 19:28:56.280230, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM]
[2011/05/10 19:28:56.280241, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.280250, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM]
[2011/05/10 19:28:56.280273, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM]
[2011/05/10 19:28:56.280294, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [SYSTEM]
[2011/05/10 19:28:56.280306, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (3)
[2011/05/10 19:28:56.280331, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM]
[2011/05/10 19:28:56.280343, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM]
[2011/05/10 19:28:56.280353, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.280363, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM]
[2011/05/10 19:28:56.280385, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM]
[2011/05/10 19:28:56.280407, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [CurrentControlSet]
[2011/05/10 19:28:56.280431, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.280445, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.280455, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.280465, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.280475, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.280506, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet]
[2011/05/10 19:28:56.280529, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.280541, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Services]
[2011/05/10 19:28:56.280553, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.280565, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.280576, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.280587, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.280597, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.280628, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services]
[2011/05/10 19:28:56.280651, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.280662, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [WINS]
[2011/05/10 19:28:56.280673, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.280686, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services/WINS]
[2011/05/10 19:28:56.280704, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services/WINS]
[2011/05/10 19:28:56.280716, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.280725, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services/WINS]
[2011/05/10 19:28:56.280749, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\WINS]
[2011/05/10 19:28:56.280772, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.280783, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (3)
[2011/05/10 19:28:56.280852, 10, pid=3533] registry/reg_backend_db.c:1663(regdb_store_values_internal)
regdb_store_values: Looking for value of key [HKLM\SYSTEM\CurrentControlSet\Services\WINS]
[2011/05/10 19:28:56.280880, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (2)
[2011/05/10 19:28:56.280895, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [HKLM]
[2011/05/10 19:28:56.280906, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (2)
[2011/05/10 19:28:56.280919, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM]
[2011/05/10 19:28:56.280929, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM]
[2011/05/10 19:28:56.280939, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.280949, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM]
[2011/05/10 19:28:56.280983, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM]
[2011/05/10 19:28:56.281005, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [SYSTEM]
[2011/05/10 19:28:56.281017, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (3)
[2011/05/10 19:28:56.281029, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM]
[2011/05/10 19:28:56.281039, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM]
[2011/05/10 19:28:56.281050, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.281059, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM]
[2011/05/10 19:28:56.281081, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM]
[2011/05/10 19:28:56.281102, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [CurrentControlSet]
[2011/05/10 19:28:56.281113, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.281126, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.281137, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.281147, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.281157, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet]
[2011/05/10 19:28:56.281181, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet]
[2011/05/10 19:28:56.281211, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.281223, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Services]
[2011/05/10 19:28:56.281234, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.281246, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.281256, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.281267, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.281276, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services]
[2011/05/10 19:28:56.281327, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services]
[2011/05/10 19:28:56.281352, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.281364, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [WINS]
[2011/05/10 19:28:56.281375, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.281388, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services/WINS]
[2011/05/10 19:28:56.281398, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services/WINS]
[2011/05/10 19:28:56.281409, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.281419, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services/WINS]
[2011/05/10 19:28:56.281443, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\WINS]
[2011/05/10 19:28:56.281465, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.281477, 7, pid=3533] registry/reg_api.c:133(regkey_open_onelevel)
regkey_open_onelevel: name = [Security]
[2011/05/10 19:28:56.281488, 10, pid=3533] registry/reg_backend_db.c:451(regdb_open)
regdb_open: incrementing refcount (4)
[2011/05/10 19:28:56.281501, 10, pid=3533] registry/reg_cachehook.c:125(reghook_cache_find)
reghook_cache_find: Searching for keyname [/HKLM/SYSTEM/CurrentControlSet/Services/WINS/Security]
[2011/05/10 19:28:56.281512, 10, pid=3533] lib/adt_tree.c:352(pathtree_find)
pathtree_find: Enter [/HKLM/SYSTEM/CurrentControlSet/Services/WINS/Security]
[2011/05/10 19:28:56.281523, 10, pid=3533] lib/adt_tree.c:425(pathtree_find)
pathtree_find: Exit
[2011/05/10 19:28:56.281532, 10, pid=3533] registry/reg_cachehook.c:130(reghook_cache_find)
reghook_cache_find: found ops 0x2b678dc89600 for key [/HKLM/SYSTEM/CurrentControlSet/Services/WINS/Security]
[2011/05/10 19:28:56.281554, 10, pid=3533] registry/reg_backend_db.c:1483(regdb_fetch_keys_internal)
regdb_fetch_keys: no subkeys found for key [HKLM\SYSTEM\CurrentControlSet\Services\WINS\Security]
[2011/05/10 19:28:56.281567, 10, pid=3533] registry/reg_backend_db.c:1726(regdb_get_secdesc)
regdb_get_secdesc: Getting secdesc of key [HKLM\SYSTEM\CurrentControlSet\Services\WINS\Security]
[2011/05/10 19:28:56.281589, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (4)
[2011/05/10 19:28:56.281600, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (3)
[2011/05/10 19:28:56.281625, 10, pid=3533] registry/reg_backend_db.c:1663(regdb_store_values_internal)
regdb_store_values: Looking for value of key [HKLM\SYSTEM\CurrentControlSet\Services\WINS\Security]
[2011/05/10 19:28:56.281650, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (2)
[2011/05/10 19:28:56.281663, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (1)
[2011/05/10 19:28:56.281723, 10, pid=3533] registry/reg_backend_db.c:485(regdb_close)
regdb_close: decrementing refcount (0)
[2011/05/10 19:28:56.281916, 10, pid=3533] printing/nt_printing.c:707(update_c_setprinter)
update_c_setprinter: c_setprinter = 0
[2011/05/10 19:28:56.282006, 6, pid=3533] libads/ldap.c:359(ads_find_dc)
ads_find_dc: (ldap) looking for realm 'child.root.PRI'
[2011/05/10 19:28:56.282046, 10, pid=3533] lib/gencache.c:345(gencache_get_data_blob)
Returning valid cache entry: key = AD_SITENAME/DOMAIN/child.root.PRI, value = Default-First-Site-Name, timeout = Mon Jan 18 22:14:07 2038
[2011/05/10 19:28:56.282079, 5, pid=3533] libads/dns.c:810(sitename_fetch)
sitename_fetch: Returning sitename for child.root.PRI: "Default-First-Site-Name"
[2011/05/10 19:28:56.282092, 4, pid=3533] libsmb/namequery_dc.c:73(ads_dc_name)
ads_dc_name: domain=TESTER
[2011/05/10 19:28:56.282116, 10, pid=3533] lib/gencache.c:345(gencache_get_data_blob)
Returning valid cache entry: key = AD_SITENAME/DOMAIN/child.root.PRI, value = Default-First-Site-Name, timeout = Mon Jan 18 22:14:07 2038
[2011/05/10 19:28:56.282132, 5, pid=3533] libads/dns.c:810(sitename_fetch)
sitename_fetch: Returning sitename for child.root.PRI: "Default-First-Site-Name"
[2011/05/10 19:28:56.282143, 6, pid=3533] libads/ldap.c:379(ads_find_dc)
ads_find_dc: (cldap) looking for realm 'child.root.PRI'
[2011/05/10 19:28:56.282158, 8, pid=3533] libsmb/namequery.c:2071(get_sorted_dc_list)
get_sorted_dc_list: attempting lookup for name child.root.PRI (sitename Default-First-Site-Name) using [ads]
[2011/05/10 19:28:56.282198, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = SAFJOIN/DOMAIN/child.root.PRI couldn't be found
[2011/05/10 19:28:56.282215, 10, pid=3533] lib/gencache.c:345(gencache_get_data_blob)
Returning expired cache entry: key = SAF/DOMAIN/child.root.PRI, value = sdom203.child.root.pri, timeout = Tue May 10 18:59:14 2011
[2011/05/10 19:28:56.282241, 10, pid=3533] lib/gencache.c:180(gencache_set_data_blob)
Adding cache entry with key = SAF/DOMAIN/child.root.PRI and timeout = Wed Dec 31 19:00:00 1969
(-1305070136 seconds in the past)
[2011/05/10 19:28:56.321543, 5, pid=3533] libsmb/namequery.c:185(saf_fetch)
saf_fetch: failed to find server for "child.root.PRI" domain
[2011/05/10 19:28:56.321593, 3, pid=3533] libsmb/namequery.c:1880(get_dc_list)
get_dc_list: preferred server list: ", *"
[2011/05/10 19:28:56.321616, 10, pid=3533] libsmb/namequery.c:1400(internal_resolve_name)
internal_resolve_name: looking up child.root.PRI#1c (sitename Default-First-Site-Name)
[2011/05/10 19:28:56.321660, 10, pid=3533] lib/gencache.c:345(gencache_get_data_blob)
Returning expired cache entry: key = NBT/child.root.PRI#1C, value = 10.215.1.29:389,10.210.2.202:389,10.210.2.201:389, timeout = Tue May 10 18:48:26 2011
[2011/05/10 19:28:56.321686, 10, pid=3533] lib/gencache.c:180(gencache_set_data_blob)
Adding cache entry with key = NBT/child.root.PRI#1C and timeout = Wed Dec 31 19:00:00 1969
(-1305070136 seconds in the past)
[2011/05/10 19:28:56.321716, 5, pid=3533] libsmb/namecache.c:188(namecache_fetch)
no entry for child.root.PRI#1C found.
[2011/05/10 19:28:56.321738, 5, pid=3533] libsmb/namequery.c:1294(resolve_ads)
resolve_ads: Attempting to resolve DCs for child.root.PRI using DNS
[2011/05/10 19:28:56.322678, 4, pid=3533] libads/dns.c:432(ads_dns_lookup_srv)
ads_dns_lookup_srv: 3 records returned in the answer section.
[2011/05/10 19:28:56.322703, 10, pid=3533] libads/dns.c:213(ads_dns_parse_rr_srv)
ads_dns_parse_rr_srv: Parsed sdom202.child.root.pri [0, 100, 389]
[2011/05/10 19:28:56.322729, 10, pid=3533] libads/dns.c:213(ads_dns_parse_rr_srv)
ads_dns_parse_rr_srv: Parsed sdom201.child.root.pri [0, 100, 389]
[2011/05/10 19:28:56.322742, 10, pid=3533] libads/dns.c:213(ads_dns_parse_rr_srv)
ads_dns_parse_rr_srv: Parsed sdom203.child.root.pri [0, 100, 389]
[2011/05/10 19:28:56.322768, 10, pid=3533] libsmb/namequery.c:572(remove_duplicate_addrs2)
remove_duplicate_addrs2: looking for duplicate address/port pairs
[2011/05/10 19:28:56.322783, 5, pid=3533] libsmb/namecache.c:106(namecache_store)
namecache_store: storing 3 addresses for child.root.PRI#1c: 10.210.2.202,10.210.2.201,10.215.1.29
[2011/05/10 19:28:56.322837, 10, pid=3533] lib/gencache.c:180(gencache_set_data_blob)
Adding cache entry with key = NBT/child.root.PRI#1C and timeout = Tue May 10 19:39:56 2011
(660 seconds ahead)
[2011/05/10 19:28:56.322880, 10, pid=3533] libsmb/namequery.c:1547(internal_resolve_name)
internal_resolve_name: returning 3 addresses: 10.210.2.202:389 10.210.2.201:389 10.215.1.29:389
[2011/05/10 19:28:56.322896, 8, pid=3533] libsmb/namequery.c:1901(get_dc_list)
Adding 3 DC's from auto lookup
[2011/05/10 19:28:56.322923, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = NEG_CONN_CACHE/child.root.PRI,10.210.2.202 couldn't be found
[2011/05/10 19:28:56.322935, 9, pid=3533] libsmb/conncache.c:150(check_negative_conn_cache)
check_negative_conn_cache returning result 0 for domain child.root.PRI server 10.210.2.202
[2011/05/10 19:28:56.322953, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = NEG_CONN_CACHE/child.root.PRI,10.210.2.201 couldn't be found
[2011/05/10 19:28:56.322964, 9, pid=3533] libsmb/conncache.c:150(check_negative_conn_cache)
check_negative_conn_cache returning result 0 for domain child.root.PRI server 10.210.2.201
[2011/05/10 19:28:56.322993, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = NEG_CONN_CACHE/child.root.PRI,10.215.1.29 couldn't be found
[2011/05/10 19:28:56.323005, 9, pid=3533] libsmb/conncache.c:150(check_negative_conn_cache)
check_negative_conn_cache returning result 0 for domain child.root.PRI server 10.215.1.29
[2011/05/10 19:28:56.323016, 10, pid=3533] libsmb/namequery.c:572(remove_duplicate_addrs2)
remove_duplicate_addrs2: looking for duplicate address/port pairs
[2011/05/10 19:28:56.323028, 4, pid=3533] libsmb/namequery.c:2020(get_dc_list)
get_dc_list: returning 3 ip addresses in an ordered list
[2011/05/10 19:28:56.323038, 4, pid=3533] libsmb/namequery.c:2021(get_dc_list)
get_dc_list: 10.210.2.202:389 10.210.2.201:389 10.215.1.29:389
[2011/05/10 19:28:56.323061, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = NEG_CONN_CACHE/child.root.PRI,10.210.2.202 couldn't be found
[2011/05/10 19:28:56.323072, 9, pid=3533] libsmb/conncache.c:150(check_negative_conn_cache)
check_negative_conn_cache returning result 0 for domain child.root.PRI server 10.210.2.202
[2011/05/10 19:28:56.323084, 5, pid=3533] libads/ldap.c:226(ads_try_connect)
ads_try_connect: sending CLDAP request to 10.210.2.202 (realm: child.root.PRI)
[2011/05/10 19:28:56.324290, 10, pid=3533] libads/dns.c:775(sitename_store)
sitename_store: realm = [KFBDOM1], sitename = [Default-First-Site-Name], expire = [2147483647]
[2011/05/10 19:28:56.324307, 10, pid=3533] lib/gencache.c:180(gencache_set_data_blob)
Adding cache entry with key = AD_SITENAME/DOMAIN/KFBDOM1 and timeout = Mon Jan 18 22:14:07 2038
(842413511 seconds ahead)
[2011/05/10 19:28:56.324336, 10, pid=3533] libads/dns.c:775(sitename_store)
sitename_store: realm = [child.root.pri], sitename = [Default-First-Site-Name], expire = [2147483647]
[2011/05/10 19:28:56.324350, 10, pid=3533] lib/gencache.c:180(gencache_set_data_blob)
Adding cache entry with key = AD_SITENAME/DOMAIN/child.root.PRI and timeout = Mon Jan 18 22:14:07 2038
(842413511 seconds ahead)
[2011/05/10 19:28:56.324401, 3, pid=3533] libads/ldap.c:634(ads_connect)
Successfully contacted LDAP server 10.210.2.202
[2011/05/10 19:28:56.324427, 10, pid=3533] lib/gencache.c:345(gencache_get_data_blob)
Returning valid cache entry: key = AD_SITENAME/DOMAIN/child.root.PRI, value = Default-First-Site-Name, timeout = Mon Jan 18 22:14:07 2038
[2011/05/10 19:28:56.324444, 5, pid=3533] libads/dns.c:810(sitename_fetch)
sitename_fetch: Returning sitename for child.root.PRI: "Default-First-Site-Name"
[2011/05/10 19:28:56.324464, 10, pid=3533] libads/ldap.c:165(ads_closest_dc)
ads_closest_dc: NBT_SERVER_CLOSEST flag set
[2011/05/10 19:28:56.324505, 10, pid=3533] libads/kerberos.c:930(create_local_private_krb5_conf_for_domain)
create_local_private_krb5_conf_for_domain: fname = /var/lib/samba/smb_krb5/krb5.conf.TESTER, realm = child.root.PRI, domain = TESTER
[2011/05/10 19:28:56.324535, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = SAFJOIN/DOMAIN/child.root.PRI couldn't be found
[2011/05/10 19:28:56.324552, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = SAF/DOMAIN/child.root.PRI couldn't be found
[2011/05/10 19:28:56.324564, 5, pid=3533] libsmb/namequery.c:185(saf_fetch)
saf_fetch: failed to find server for "child.root.PRI" domain
[2011/05/10 19:28:56.324577, 3, pid=3533] libsmb/namequery.c:1880(get_dc_list)
get_dc_list: preferred server list: ", *"
[2011/05/10 19:28:56.324590, 10, pid=3533] libsmb/namequery.c:1400(internal_resolve_name)
internal_resolve_name: looking up child.root.PRI#1c (sitename Default-First-Site-Name)
[2011/05/10 19:28:56.324605, 10, pid=3533] lib/gencache.c:345(gencache_get_data_blob)
Returning valid cache entry: key = NBT/child.root.PRI#1C, value = 10.210.2.202:389,10.210.2.201:389,10.215.1.29:389, timeout = Tue May 10 19:39:56 2011
[2011/05/10 19:28:56.324622, 5, pid=3533] libsmb/namecache.c:192(namecache_fetch)
name child.root.PRI#1C found.
[2011/05/10 19:28:56.324678, 8, pid=3533] libsmb/namequery.c:1901(get_dc_list)
Adding 3 DC's from auto lookup
[2011/05/10 19:28:56.324699, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = NEG_CONN_CACHE/child.root.PRI,10.210.2.202 couldn't be found
[2011/05/10 19:28:56.324711, 9, pid=3533] libsmb/conncache.c:150(check_negative_conn_cache)
check_negative_conn_cache returning result 0 for domain child.root.PRI server 10.210.2.202
[2011/05/10 19:28:56.324730, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = NEG_CONN_CACHE/child.root.PRI,10.210.2.201 couldn't be found
[2011/05/10 19:28:56.324741, 9, pid=3533] libsmb/conncache.c:150(check_negative_conn_cache)
check_negative_conn_cache returning result 0 for domain child.root.PRI server 10.210.2.201
[2011/05/10 19:28:56.324759, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = NEG_CONN_CACHE/child.root.PRI,10.215.1.29 couldn't be found
[2011/05/10 19:28:56.324770, 9, pid=3533] libsmb/conncache.c:150(check_negative_conn_cache)
check_negative_conn_cache returning result 0 for domain child.root.PRI server 10.215.1.29
[2011/05/10 19:28:56.324781, 10, pid=3533] libsmb/namequery.c:572(remove_duplicate_addrs2)
remove_duplicate_addrs2: looking for duplicate address/port pairs
[2011/05/10 19:28:56.324793, 4, pid=3533] libsmb/namequery.c:2020(get_dc_list)
get_dc_list: returning 3 ip addresses in an ordered list
[2011/05/10 19:28:56.324804, 4, pid=3533] libsmb/namequery.c:2021(get_dc_list)
get_dc_list: 10.210.2.202:389 10.210.2.201:389 10.215.1.29:389
[2011/05/10 19:28:56.324831, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = SAFJOIN/DOMAIN/child.root.PRI couldn't be found
[2011/05/10 19:28:56.324847, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = SAF/DOMAIN/child.root.PRI couldn't be found
[2011/05/10 19:28:56.324858, 5, pid=3533] libsmb/namequery.c:185(saf_fetch)
saf_fetch: failed to find server for "child.root.PRI" domain
[2011/05/10 19:28:56.324890, 3, pid=3533] libsmb/namequery.c:1880(get_dc_list)
get_dc_list: preferred server list: ", *"
[2011/05/10 19:28:56.324908, 10, pid=3533] libsmb/namequery.c:1400(internal_resolve_name)
internal_resolve_name: looking up child.root.PRI#1c (sitename (null))
[2011/05/10 19:28:56.324923, 10, pid=3533] lib/gencache.c:345(gencache_get_data_blob)
Returning valid cache entry: key = NBT/child.root.PRI#1C, value = 10.210.2.202:389,10.210.2.201:389,10.215.1.29:389, timeout = Tue May 10 19:39:56 2011
[2011/05/10 19:28:56.324939, 5, pid=3533] libsmb/namecache.c:192(namecache_fetch)
name child.root.PRI#1C found.
[2011/05/10 19:28:56.325004, 8, pid=3533] libsmb/namequery.c:1901(get_dc_list)
Adding 3 DC's from auto lookup
[2011/05/10 19:28:56.325025, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = NEG_CONN_CACHE/child.root.PRI,10.210.2.202 couldn't be found
[2011/05/10 19:28:56.325036, 9, pid=3533] libsmb/conncache.c:150(check_negative_conn_cache)
check_negative_conn_cache returning result 0 for domain child.root.PRI server 10.210.2.202
[2011/05/10 19:28:56.325053, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = NEG_CONN_CACHE/child.root.PRI,10.210.2.201 couldn't be found
[2011/05/10 19:28:56.325065, 9, pid=3533] libsmb/conncache.c:150(check_negative_conn_cache)
check_negative_conn_cache returning result 0 for domain child.root.PRI server 10.210.2.201
[2011/05/10 19:28:56.325082, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = NEG_CONN_CACHE/child.root.PRI,10.215.1.29 couldn't be found
[2011/05/10 19:28:56.325092, 9, pid=3533] libsmb/conncache.c:150(check_negative_conn_cache)
check_negative_conn_cache returning result 0 for domain child.root.PRI server 10.215.1.29
[2011/05/10 19:28:56.325103, 10, pid=3533] libsmb/namequery.c:572(remove_duplicate_addrs2)
remove_duplicate_addrs2: looking for duplicate address/port pairs
[2011/05/10 19:28:56.325114, 4, pid=3533] libsmb/namequery.c:2020(get_dc_list)
get_dc_list: returning 3 ip addresses in an ordered list
[2011/05/10 19:28:56.325125, 4, pid=3533] libsmb/namequery.c:2021(get_dc_list)
get_dc_list: 10.210.2.202:389 10.210.2.201:389 10.215.1.29:389
[2011/05/10 19:28:56.325153, 10, pid=3533] libads/kerberos.c:875(get_kdc_ip_string)
get_kdc_ip_string: Returning kdc = 10.210.2.202
kdc = 10.210.2.201
kdc = 10.215.1.29
kdc = 10.210.2.201
kdc = 10.215.1.29
[2011/05/10 19:28:56.325515, 5, pid=3533] libads/kerberos.c:998(create_local_private_krb5_conf_for_domain)
create_local_private_krb5_conf_for_domain: wrote file /var/lib/samba/smb_krb5/krb5.conf.TESTER with realm child.root.PRI KDC list = kdc = 10.210.2.202
kdc = 10.210.2.201
kdc = 10.215.1.29
kdc = 10.210.2.201
kdc = 10.215.1.29
[2011/05/10 19:28:56.325549, 4, pid=3533] libsmb/namequery_dc.c:145(ads_dc_name)
ads_dc_name: using server='SDOM202.child.root.PRI' IP=10.210.2.202
[2011/05/10 19:28:56.325568, 10, pid=3533] lib/gencache.c:345(gencache_get_data_blob)
Returning valid cache entry: key = AD_SITENAME/DOMAIN/child.root.PRI, value = Default-First-Site-Name, timeout = Mon Jan 18 22:14:07 2038
[2011/05/10 19:28:56.325584, 5, pid=3533] libads/dns.c:810(sitename_fetch)
sitename_fetch: Returning sitename for child.root.PRI: "Default-First-Site-Name"
[2011/05/10 19:28:56.325596, 10, pid=3533] libsmb/namequery.c:1400(internal_resolve_name)
internal_resolve_name: looking up SDOM202.child.root.PRI#20 (sitename Default-First-Site-Name)
[2011/05/10 19:28:56.325613, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = NBT/SDOM202.child.root.PRI#20 couldn't be found
[2011/05/10 19:28:56.325624, 5, pid=3533] libsmb/namecache.c:188(namecache_fetch)
no entry for SDOM202.child.root.PRI#20 found.
[2011/05/10 19:28:56.325637, 3, pid=3533] libsmb/namequery.c:1119(resolve_lmhosts)
resolve_lmhosts: Attempting lmhosts lookup for name SDOM202.child.root.PRI<0x20>
[2011/05/10 19:28:56.325672, 4, pid=3533] ../libcli/nbt/lmhosts.c:110(getlmhostsent)
getlmhostsent: lmhost entry: 127.0.0.1 localhost
[2011/05/10 19:28:56.325715, 3, pid=3533] libsmb/namequery.c:983(resolve_wins)
resolve_wins: Attempting wins lookup for name SDOM202.child.root.PRI<0x20>
[2011/05/10 19:28:56.325729, 3, pid=3533] libsmb/namequery.c:987(resolve_wins)
resolve_wins: WINS server resolution selected and no WINS servers listed.
[2011/05/10 19:28:56.325739, 3, pid=3533] libsmb/namequery.c:1201(resolve_hosts)
resolve_hosts: Attempting host lookup for name SDOM202.child.root.PRI<0x20>
[2011/05/10 19:28:56.329241, 10, pid=3533] libsmb/namequery.c:572(remove_duplicate_addrs2)
remove_duplicate_addrs2: looking for duplicate address/port pairs
[2011/05/10 19:28:56.329282, 5, pid=3533] libsmb/namecache.c:106(namecache_store)
namecache_store: storing 1 address for SDOM202.child.root.PRI#20: 10.210.2.202
[2011/05/10 19:28:56.329322, 10, pid=3533] lib/gencache.c:180(gencache_set_data_blob)
Adding cache entry with key = NBT/SDOM202.child.root.PRI#20 and timeout = Tue May 10 19:39:56 2011
(660 seconds ahead)
[2011/05/10 19:28:56.329367, 10, pid=3533] libsmb/namequery.c:1547(internal_resolve_name)
internal_resolve_name: returning 1 addresses: 10.210.2.202:0
[2011/05/10 19:28:56.329384, 5, pid=3533] libads/ldap.c:226(ads_try_connect)
ads_try_connect: sending CLDAP request to 10.210.2.202 (realm: child.root.PRI)
[2011/05/10 19:28:56.330078, 10, pid=3533] libads/dns.c:775(sitename_store)
sitename_store: realm = [KFBDOM1], sitename = [Default-First-Site-Name], expire = [2147483647]
[2011/05/10 19:28:56.330094, 10, pid=3533] lib/gencache.c:180(gencache_set_data_blob)
Adding cache entry with key = AD_SITENAME/DOMAIN/KFBDOM1 and timeout = Mon Jan 18 22:14:07 2038
(842413511 seconds ahead)
[2011/05/10 19:28:56.330120, 10, pid=3533] libads/dns.c:775(sitename_store)
sitename_store: realm = [child.root.pri], sitename = [Default-First-Site-Name], expire = [2147483647]
[2011/05/10 19:28:56.330134, 10, pid=3533] lib/gencache.c:180(gencache_set_data_blob)
Adding cache entry with key = AD_SITENAME/DOMAIN/child.root.PRI and timeout = Mon Jan 18 22:14:07 2038
(842413511 seconds ahead)
[2011/05/10 19:28:56.330162, 3, pid=3533] libads/ldap.c:634(ads_connect)
Successfully contacted LDAP server 10.210.2.202
[2011/05/10 19:28:56.330177, 10, pid=3533] libads/ldap.c:62(ldap_open_with_timeout)
Opening connection to LDAP server 'SDOM202.child.root.pri:389', timeout 15 seconds
[2011/05/10 19:28:56.332558, 10, pid=3533] libads/ldap.c:76(ldap_open_with_timeout)
Connected to LDAP server 'SDOM202.child.root.pri:389'
[2011/05/10 19:28:56.332593, 3, pid=3533] libads/ldap.c:688(ads_connect)
Connected to LDAP server SDOM202.child.root.pri
[2011/05/10 19:28:56.332605, 10, pid=3533] libads/ldap.c:165(ads_closest_dc)
ads_closest_dc: NBT_SERVER_CLOSEST flag set
[2011/05/10 19:28:56.332619, 10, pid=3533] libsmb/namequery.c:83(saf_store)
saf_store: domain = [KFBDOM1], server = [SDOM202.child.root.pri], expire = [1305071036]
[2011/05/10 19:28:56.332634, 10, pid=3533] lib/gencache.c:180(gencache_set_data_blob)
Adding cache entry with key = SAF/DOMAIN/KFBDOM1 and timeout = Tue May 10 19:43:56 2011
(900 seconds ahead)
[2011/05/10 19:28:56.332669, 10, pid=3533] libsmb/namequery.c:83(saf_store)
saf_store: domain = [child.root.PRI], server = [SDOM202.child.root.pri], expire = [1305071036]
[2011/05/10 19:28:56.332683, 10, pid=3533] lib/gencache.c:180(gencache_set_data_blob)
Adding cache entry with key = SAF/DOMAIN/child.root.PRI and timeout = Tue May 10 19:43:56 2011
(900 seconds ahead)
[2011/05/10 19:28:56.333441, 4, pid=3533] libads/ldap.c:2852(ads_current_time)
time offset is -21 seconds
[2011/05/10 19:28:56.333910, 4, pid=3533] libads/sasl.c:1113(ads_sasl_bind)
Found SASL mechanism GSS-SPNEGO
[2011/05/10 19:28:56.334564, 3, pid=3533] libads/sasl.c:781(ads_sasl_spnego_bind)
ads_sasl_spnego_bind: got OID=1.3.6.1.4.1.311.2.2.30
[2011/05/10 19:28:56.334599, 3, pid=3533] libads/sasl.c:781(ads_sasl_spnego_bind)
ads_sasl_spnego_bind: got OID=1.2.840.48018.1.2.2
[2011/05/10 19:28:56.334673, 3, pid=3533] libads/sasl.c:781(ads_sasl_spnego_bind)
ads_sasl_spnego_bind: got OID=1.2.840.113554.1.2.2
[2011/05/10 19:28:56.334685, 3, pid=3533] libads/sasl.c:781(ads_sasl_spnego_bind)
ads_sasl_spnego_bind: got OID=1.2.840.113554.1.2.2.3
[2011/05/10 19:28:56.334697, 3, pid=3533] libads/sasl.c:781(ads_sasl_spnego_bind)
ads_sasl_spnego_bind: got OID=1.3.6.1.4.1.311.2.2.10
[2011/05/10 19:28:56.334707, 3, pid=3533] libads/sasl.c:790(ads_sasl_spnego_bind)
ads_sasl_spnego_bind: got server principal name = not_defined_in_RFC4178@please_ignore
[2011/05/10 19:28:56.335787, 3, pid=3533] libsmb/clikrb5.c:698(ads_krb5_mk_req)
ads_krb5_mk_req: krb5_cc_get_principal failed (No credentials cache found)
[2011/05/10 19:28:56.335846, 10, pid=3533] libads/sasl.c:811(ads_sasl_spnego_bind)
ads_sasl_spnego_krb5_bind failed with: No credentials cache found, calling kinit
[2011/05/10 19:28:56.335906, 3, pid=3533] printing/nt_printing.c:3306(check_published_printers)
ads_connect failed: Cannot read password
[2011/05/10 19:28:56.336185, 0, pid=3533] printing/nt_printing.c:629(nt_printing_init)
nt_printing_init: error checking published printers: WERR_ACCESS_DENIED
[2011/05/10 19:28:56.336492, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.336508, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.336519, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.336535, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.336550, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.336580, 6, pid=3533] passdb/pdb_interface.c:285(pdb_getsampwsid)
pdb_getsampwsid: Building guest account
[2011/05/10 19:28:56.336666, 10, pid=3533] passdb/pdb_get_set.c:608(pdb_set_username)
pdb_set_username: setting username nobody, was
[2011/05/10 19:28:56.336697, 10, pid=3533] passdb/pdb_get_set.c:677(pdb_set_fullname)
pdb_set_full_name: setting full name Nobody, was
[2011/05/10 19:28:56.336711, 10, pid=3533] passdb/pdb_get_set.c:631(pdb_set_domain)
pdb_set_domain: setting domain NPSMTP000, was
[2011/05/10 19:28:56.336727, 10, pid=3533] passdb/pdb_get_set.c:537(pdb_set_user_sid)
pdb_set_user_sid: setting user sid S-1-5-21-2259228400-3590826457-3691477811-501
[2011/05/10 19:28:56.336741, 10, pid=3533] passdb/pdb_compat.c:72(pdb_set_user_sid_from_rid)
pdb_set_user_sid_from_rid:
setting user sid S-1-5-21-2259228400-3590826457-3691477811-501 from rid 501
[2011/05/10 19:28:56.336762, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.336867, 10, pid=3533] lib/system_smbd.c:122(sys_getgrouplist)
sys_getgrouplist: user [nobody]
[2011/05/10 19:28:56.337848, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = IDMAP/GID2SID/99 couldn't be found
[2011/05/10 19:28:56.337915, 5, pid=3533] passdb/lookup_sid.c:1387(gid_to_sid)
gid_to_sid: winbind failed to find a sid for gid 99
[2011/05/10 19:28:56.337930, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.337943, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.337977, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.337989, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.337999, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.338053, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.338079, 10, pid=3533] passdb/lookup_sid.c:1182(legacy_gid_to_sid)
LEGACY: gid 99 -> sid S-1-22-2-99
[2011/05/10 19:28:56.338095, 5, pid=3533] auth/auth_util.c:649(make_server_info_sam)
make_server_info_sam: made server info for user nobody -> nobody
[2011/05/10 19:28:56.338179, 10, pid=3533] passdb/lookup_sid.c:69(lookup_name)
lookup_name: NPSMTP000\nobody => NPSMTP000 (domain), nobody (name)
[2011/05/10 19:28:56.338193, 10, pid=3533] passdb/lookup_sid.c:70(lookup_name)
lookup_name: flags = 0x073
[2011/05/10 19:28:56.338211, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.338223, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.338233, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.338243, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.338267, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.338293, 5, pid=3533] passdb/pdb_tdb.c:557(tdbsam_getsampwnam)
pdb_getsampwnam (TDB): error fetching database.
Key: USER_nobody
[2011/05/10 19:28:56.338310, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.338323, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.338334, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.338344, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.338354, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.338365, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.338411, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.338433, 10, pid=3533] passdb/lookup_sid.c:69(lookup_name)
lookup_name: Unix User\nobody => Unix User (domain), nobody (name)
[2011/05/10 19:28:56.338449, 10, pid=3533] passdb/lookup_sid.c:70(lookup_name)
lookup_name: flags = 0x073
[2011/05/10 19:28:56.338547, 10, pid=3533] passdb/lookup_sid.c:1427(sid_to_uid)
sid S-1-22-1-99 -> uid 99
[2011/05/10 19:28:56.338621, 10, pid=3533] lib/system_smbd.c:122(sys_getgrouplist)
sys_getgrouplist: user [nobody]
[2011/05/10 19:28:56.338731, 10, pid=3533] auth/token_util.c:356(create_local_nt_token)
Create local NT token for S-1-22-1-99
[2011/05/10 19:28:56.338756, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = IDMAP/SID2GID/S-1-5-32-544 couldn't be found
[2011/05/10 19:28:56.338817, 10, pid=3533] passdb/lookup_sid.c:1511(sid_to_gid)
winbind failed to find a gid for sid S-1-5-32-544
[2011/05/10 19:28:56.338832, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.338844, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.338854, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.338864, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.338874, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.338920, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.338933, 10, pid=3533] passdb/lookup_sid.c:1256(legacy_sid_to_gid)
LEGACY: mapping failed for sid S-1-5-32-544
[2011/05/10 19:28:56.338950, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.338991, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.339001, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.339012, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.339021, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.339046, 3, pid=3533] auth/token_util.c:436(create_local_nt_token)
Failed to fetch domain sid for TESTER
[2011/05/10 19:28:56.339060, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.339079, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = IDMAP/SID2GID/S-1-5-32-545 couldn't be found
[2011/05/10 19:28:56.339140, 10, pid=3533] passdb/lookup_sid.c:1511(sid_to_gid)
winbind failed to find a gid for sid S-1-5-32-545
[2011/05/10 19:28:56.339154, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.339165, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.339175, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.339186, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.339195, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.339236, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.339248, 10, pid=3533] passdb/lookup_sid.c:1256(legacy_sid_to_gid)
LEGACY: mapping failed for sid S-1-5-32-545
[2011/05/10 19:28:56.339274, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.339286, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.339296, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.339306, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.339316, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.339336, 3, pid=3533] auth/token_util.c:467(create_local_nt_token)
Failed to fetch domain sid for TESTER
[2011/05/10 19:28:56.339350, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.339362, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.339373, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.339383, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.339393, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.339402, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.339531, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.339551, 3, pid=3533] lib/privileges.c:63(get_privileges)
get_privileges: No privileges assigned to SID [S-1-22-1-99]
[2011/05/10 19:28:56.339568, 3, pid=3533] lib/privileges.c:63(get_privileges)
get_privileges: No privileges assigned to SID [S-1-22-2-99]
[2011/05/10 19:28:56.339584, 5, pid=3533] lib/privileges.c:128(get_privileges_for_sids)
get_privileges_for_sids: sid = S-1-1-0
Privilege set:
SE_PRIV 0x0 0x0 0x0 0x0
[2011/05/10 19:28:56.339615, 3, pid=3533] lib/privileges.c:63(get_privileges)
get_privileges: No privileges assigned to SID [S-1-5-2]
[2011/05/10 19:28:56.339631, 3, pid=3533] lib/privileges.c:63(get_privileges)
get_privileges: No privileges assigned to SID [S-1-5-32-546]
[2011/05/10 19:28:56.339651, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = IDMAP/SID2GID/S-1-1-0 couldn't be found
[2011/05/10 19:28:56.339714, 10, pid=3533] passdb/lookup_sid.c:1511(sid_to_gid)
winbind failed to find a gid for sid S-1-1-0
[2011/05/10 19:28:56.339729, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.339740, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.339750, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.339760, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.339770, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.339809, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.339822, 10, pid=3533] passdb/lookup_sid.c:1256(legacy_sid_to_gid)
LEGACY: mapping failed for sid S-1-1-0
[2011/05/10 19:28:56.339833, 10, pid=3533] auth/auth_util.c:753(create_local_token)
Could not convert SID S-1-1-0 to gid, ignoring it
[2011/05/10 19:28:56.339851, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = IDMAP/SID2GID/S-1-5-2 couldn't be found
[2011/05/10 19:28:56.339910, 10, pid=3533] passdb/lookup_sid.c:1511(sid_to_gid)
winbind failed to find a gid for sid S-1-5-2
[2011/05/10 19:28:56.339925, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.339936, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.339946, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.340019, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.340030, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.340069, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.340082, 10, pid=3533] passdb/lookup_sid.c:1256(legacy_sid_to_gid)
LEGACY: mapping failed for sid S-1-5-2
[2011/05/10 19:28:56.340093, 10, pid=3533] auth/auth_util.c:753(create_local_token)
Could not convert SID S-1-5-2 to gid, ignoring it
[2011/05/10 19:28:56.340112, 10, pid=3533] lib/gencache.c:334(gencache_get_data_blob)
Cache entry with key = IDMAP/SID2GID/S-1-5-32-546 couldn't be found
[2011/05/10 19:28:56.340172, 10, pid=3533] passdb/lookup_sid.c:1511(sid_to_gid)
winbind failed to find a gid for sid S-1-5-32-546
[2011/05/10 19:28:56.340187, 3, pid=3533] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.340198, 3, pid=3533] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:28:56.340208, 3, pid=3533] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:28:56.340218, 5, pid=3533] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:28:56.340227, 5, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:28:56.340294, 3, pid=3533] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:28:56.340309, 10, pid=3533] passdb/lookup_sid.c:1256(legacy_sid_to_gid)
LEGACY: mapping failed for sid S-1-5-32-546
[2011/05/10 19:28:56.340321, 10, pid=3533] auth/auth_util.c:753(create_local_token)
Could not convert SID S-1-5-32-546 to gid, ignoring it
[2011/05/10 19:28:56.340342, 10, pid=3533] auth/token_util.c:531(debug_nt_user_token)
NT user token of user S-1-22-1-99
contains 5 SIDs
SID[ 0]: S-1-22-1-99
SID[ 1]: S-1-22-2-99
SID[ 2]: S-1-1-0
SID[ 3]: S-1-5-2
SID[ 4]: S-1-5-32-546
SE_PRIV 0x0 0x0 0x0 0x0
[2011/05/10 19:28:56.340377, 10, pid=3533] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 99
Primary group is 99 and contains 1 supplementary groups
Group[ 0]: 99
[2011/05/10 19:28:56.340484, 3, pid=3533] printing/printing.c:1412(start_background_queue)
start_background_queue: Starting background LPQ thread
[2011/05/10 19:28:56.342166, 5, pid=3536] printing/printing.c:1434(start_background_queue)
start_background_queue: background LPQ thread started
[2011/05/10 19:28:56.343049, 5, pid=3536] smbd/connection.c:142(claim_connection)
claiming [smbd lpq backend]
[2011/05/10 19:28:56.343360, 10, pid=3536] lib/dbwrap_tdb.c:100(db_tdb_fetch_locked)
Locking key D00D0000FFFFFFFFFFFF
[2011/05/10 19:28:56.343476, 10, pid=3536] lib/dbwrap_tdb.c:129(db_tdb_fetch_locked)
Allocated locked data 0x0x2b67a27e14c0
[2011/05/10 19:28:56.343539, 10, pid=3536] lib/dbwrap_tdb.c:42(db_tdb_record_destr)
Unlocking key D00D0000FFFFFFFFFFFF
[2011/05/10 19:28:56.343620, 5, pid=3536] printing/printing.c:1468(start_background_queue)
start_background_queue: background LPQ thread waiting for messages
[2011/05/10 19:28:56.344013, 10, pid=3533] lib/util_sock.c:893(open_socket_in)
bind succeeded on port 445
[2011/05/10 19:28:56.344054, 5, pid=3533] lib/util_sock.c:304(print_socket_options)
Socket options:
SO_KEEPALIVE = 1
SO_REUSEADDR = 1
SO_BROADCAST = 0
TCP_NODELAY = 0
TCP_KEEPCNT = 9
TCP_KEEPIDLE = 7200
TCP_KEEPINTVL = 75
IPTOS_LOWDELAY = 0
IPTOS_THROUGHPUT = 0
SO_SNDBUF = 16384
SO_RCVBUF = 87380
SO_SNDLOWAT = 1
SO_RCVLOWAT = 1
SO_SNDTIMEO = 0
SO_RCVTIMEO = 0
TCP_QUICKACK = 1
[2011/05/10 19:28:56.344130, 5, pid=3533] lib/util_sock.c:304(print_socket_options)
Socket options:
SO_KEEPALIVE = 1
SO_REUSEADDR = 1
SO_BROADCAST = 0
TCP_NODELAY = 1
TCP_KEEPCNT = 9
TCP_KEEPIDLE = 7200
TCP_KEEPINTVL = 75
IPTOS_LOWDELAY = 0
IPTOS_THROUGHPUT = 0
SO_SNDBUF = 16384
SO_RCVBUF = 87380
SO_SNDLOWAT = 1
SO_RCVLOWAT = 1
SO_SNDTIMEO = 0
SO_RCVTIMEO = 0
TCP_QUICKACK = 1
[2011/05/10 19:28:56.344238, 10, pid=3533] lib/util_sock.c:893(open_socket_in)
bind succeeded on port 139
[2011/05/10 19:28:56.344252, 5, pid=3533] lib/util_sock.c:304(print_socket_options)
Socket options:
SO_KEEPALIVE = 1
SO_REUSEADDR = 1
SO_BROADCAST = 0
TCP_NODELAY = 0
TCP_KEEPCNT = 9
TCP_KEEPIDLE = 7200
TCP_KEEPINTVL = 75
IPTOS_LOWDELAY = 0
IPTOS_THROUGHPUT = 0
SO_SNDBUF = 16384
SO_RCVBUF = 87380
SO_SNDLOWAT = 1
SO_RCVLOWAT = 1
SO_SNDTIMEO = 0
SO_RCVTIMEO = 0
TCP_QUICKACK = 1
[2011/05/10 19:28:56.344337, 5, pid=3533] lib/util_sock.c:304(print_socket_options)
Socket options:
SO_KEEPALIVE = 1
SO_REUSEADDR = 1
SO_BROADCAST = 0
TCP_NODELAY = 1
TCP_KEEPCNT = 9
TCP_KEEPIDLE = 7200
TCP_KEEPINTVL = 75
IPTOS_LOWDELAY = 0
IPTOS_THROUGHPUT = 0
SO_SNDBUF = 16384
SO_RCVBUF = 87380
SO_SNDLOWAT = 1
SO_RCVLOWAT = 1
SO_SNDTIMEO = 0
SO_RCVTIMEO = 0
TCP_QUICKACK = 1
[2011/05/10 19:28:56.344474, 2, pid=3533] lib/util_sock.c:880(open_socket_in)
bind failed on port 445 socket_addr = 0.0.0.0.
Error = Address already in use
[2011/05/10 19:28:56.344798, 0, pid=3533] smbd/server.c:500(smbd_open_one_socket)
smbd_open_once_socket: open_socket_in: Address already in use
[2011/05/10 19:28:56.344893, 2, pid=3533] lib/util_sock.c:880(open_socket_in)
bind failed on port 139 socket_addr = 0.0.0.0.
Error = Address already in use
[2011/05/10 19:28:56.344915, 0, pid=3533] smbd/server.c:500(smbd_open_one_socket)
smbd_open_once_socket: open_socket_in: Address already in use
[2011/05/10 19:28:56.344948, 5, pid=3533] smbd/connection.c:142(claim_connection)
claiming []
[2011/05/10 19:28:56.345134, 10, pid=3533] lib/dbwrap_tdb.c:100(db_tdb_fetch_locked)
Locking key CD0D0000FFFFFFFFFFFF
[2011/05/10 19:28:56.345184, 10, pid=3533] lib/dbwrap_tdb.c:129(db_tdb_fetch_locked)
Allocated locked data 0x0x2b67a27e1d00
[2011/05/10 19:28:56.345223, 10, pid=3533] lib/dbwrap_tdb.c:42(db_tdb_record_destr)
Unlocking key CD0D0000FFFFFFFFFFFF
[2011/05/10 19:28:56.345273, 5, pid=3533] lib/messages.c:297(messaging_register)
Overriding messaging pointer for type 1 - private_data=(nil)
[2011/05/10 19:28:56.345865, 2, pid=3533] smbd/server.c:721(smbd_parent_loop)
waiting for connections
[2011/05/10 19:29:03.063353, 5, pid=3537] lib/util_sock.c:304(print_socket_options)
Socket options:
SO_KEEPALIVE = 1
SO_REUSEADDR = 1
SO_BROADCAST = 0
TCP_NODELAY = 1
TCP_KEEPCNT = 9
TCP_KEEPIDLE = 7200
TCP_KEEPINTVL = 75
IPTOS_LOWDELAY = 0
IPTOS_THROUGHPUT = 0
SO_SNDBUF = 16384
SO_RCVBUF = 87380
SO_SNDLOWAT = 1
SO_RCVLOWAT = 1
SO_SNDTIMEO = 0
SO_RCVTIMEO = 0
TCP_QUICKACK = 1
[2011/05/10 19:29:03.063611, 5, pid=3537] lib/util_sock.c:304(print_socket_options)
Socket options:
SO_KEEPALIVE = 1
SO_REUSEADDR = 1
SO_BROADCAST = 0
TCP_NODELAY = 1
TCP_KEEPCNT = 9
TCP_KEEPIDLE = 7200
TCP_KEEPINTVL = 75
IPTOS_LOWDELAY = 0
IPTOS_THROUGHPUT = 0
SO_SNDBUF = 16384
SO_RCVBUF = 87380
SO_SNDLOWAT = 1
SO_RCVLOWAT = 1
SO_SNDTIMEO = 0
SO_RCVTIMEO = 0
TCP_QUICKACK = 1
[2011/05/10 19:29:03.064236, 6, pid=3537] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:03.064725, 3, pid=3537] smbd/oplock.c:894(init_oplocks)
init_oplocks: initializing messages.
[2011/05/10 19:29:03.064839, 3, pid=3537] smbd/oplock_linux.c:224(linux_init_kernel_oplocks)
Linux kernel oplocks enabled
[2011/05/10 19:29:03.064859, 5, pid=3537] lib/messages.c:329(messaging_deregister)
Deregistering messaging pointer for type 1 - private_data=(nil)
[2011/05/10 19:29:03.064955, 10, pid=3537] smbd/process.c:740(event_add_idle)
event_add_idle: idle_evt(keepalive) 0x2b67a274f930
[2011/05/10 19:29:03.064975, 10, pid=3537] smbd/process.c:740(event_add_idle)
event_add_idle: idle_evt(deadtime) 0x2b67a2758220
[2011/05/10 19:29:03.064989, 10, pid=3537] smbd/process.c:740(event_add_idle)
event_add_idle: idle_evt(housekeeping) 0x2b67a27450e0
[2011/05/10 19:29:03.065077, 10, pid=3537] lib/util_sock.c:731(read_smb_length_return_keepalive)
got smb length of 68
[2011/05/10 19:29:03.065103, 6, pid=3537] smbd/process.c:1482(process_smb)
got message type 0x81 of len 0x44
[2011/05/10 19:29:03.065121, 3, pid=3537] smbd/process.c:1485(process_smb)
Transaction 0 of length 72 (0 toread)
[2011/05/10 19:29:03.065157, 2, pid=3537] smbd/reply.c:536(reply_special)
netbios connect: name1=NPSMTP000 0x20 name2=SXCH101 0x0
[2011/05/10 19:29:03.065220, 2, pid=3537] smbd/reply.c:547(reply_special)
netbios connect: local=npsmtp000 remote=sxch101, name type = 0
[2011/05/10 19:29:03.065241, 6, pid=3537] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:03.065279, 5, pid=3537] smbd/reply.c:587(reply_special)
init msg_type=0x81 msg_flags=0x0
[2011/05/10 19:29:03.066388, 10, pid=3537] lib/util_sock.c:731(read_smb_length_return_keepalive)
got smb length of 133
[2011/05/10 19:29:03.066421, 6, pid=3537] smbd/process.c:1482(process_smb)
got message type 0x0 of len 0x85
[2011/05/10 19:29:03.066438, 3, pid=3537] smbd/process.c:1485(process_smb)
Transaction 0 of length 137 (0 toread)
[2011/05/10 19:29:03.066453, 5, pid=3537] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.066460, 5, pid=3537] lib/util.c:627(show_msg)
size=133
smb_com=0x72
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51283
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=0
smt_wct=0
smb_bcc=98
[2011/05/10 19:29:03.066528, 10, pid=3537] ../lib/util/util.c:278(_dump_data)
[0000] 02 50 43 20 4E 45 54 57 4F 52 4B 20 50 52 4F 47 .PC NETW ORK PROG
[0010] 52 41 4D 20 31 2E 30 00 02 4C 41 4E 4D 41 4E 31 RAM 1.0. .LANMAN1
[0020] 2E 30 00 02 57 69 6E 64 6F 77 73 20 66 6F 72 20 .0..Wind ows for
[0030] 57 6F 72 6B 67 72 6F 75 70 73 20 33 2E 31 61 00 Workgrou ps 3.1a.
[0040] 02 4C 4D 31 2E 32 58 30 30 32 00 02 4C 41 4E 4D .LM1.2X0 02..LANM
[0050] 41 4E 32 2E 31 00 02 4E 54 20 4C 4D 20 30 2E 31 AN2.1..N T LM 0.1
[0060] 32 00 2.
[2011/05/10 19:29:03.066670, 3, pid=3537] smbd/process.c:1294(switch_message)
switch message SMBnegprot (pid 3537) conn 0x0
[2011/05/10 19:29:03.066693, 3, pid=3537] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:03.066717, 5, pid=3537] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:03.066734, 5, pid=3537] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:03.066787, 5, pid=3537] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:03.066964, 3, pid=3537] smbd/negprot.c:586(reply_negprot)
Requested protocol [PC NETWORK PROGRAM 1.0]
[2011/05/10 19:29:03.066985, 3, pid=3537] smbd/negprot.c:586(reply_negprot)
Requested protocol [LANMAN1.0]
[2011/05/10 19:29:03.066997, 3, pid=3537] smbd/negprot.c:586(reply_negprot)
Requested protocol [Windows for Workgroups 3.1a]
[2011/05/10 19:29:03.067009, 3, pid=3537] smbd/negprot.c:586(reply_negprot)
Requested protocol [LM1.2X002]
[2011/05/10 19:29:03.067020, 3, pid=3537] smbd/negprot.c:586(reply_negprot)
Requested protocol [LANMAN2.1]
[2011/05/10 19:29:03.067031, 3, pid=3537] smbd/negprot.c:586(reply_negprot)
Requested protocol [NT LM 0.12]
[2011/05/10 19:29:03.067051, 10, pid=3537] lib/util.c:1969(set_remote_arch)
set_remote_arch: Client arch is 'Win2K'
[2011/05/10 19:29:03.067077, 6, pid=3537] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:03.067105, 5, pid=3537] smbd/connection.c:142(claim_connection)
claiming []
[2011/05/10 19:29:03.067168, 10, pid=3537] lib/dbwrap_tdb.c:100(db_tdb_fetch_locked)
Locking key D10D0000FFFFFFFFFFFF
[2011/05/10 19:29:03.067233, 10, pid=3537] lib/dbwrap_tdb.c:129(db_tdb_fetch_locked)
Allocated locked data 0x0x2b67a27e6f90
[2011/05/10 19:29:03.067314, 10, pid=3537] lib/dbwrap_tdb.c:42(db_tdb_record_destr)
Unlocking key D10D0000FFFFFFFFFFFF
[2011/05/10 19:29:03.067397, 6, pid=3537] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:03.067642, 10, pid=3537] lib/util.c:2598(name_to_fqdn)
name_to_fqdn: lookup for NPSMTP000 -> npsmtp000.child.root.pri.
[2011/05/10 19:29:03.067711, 3, pid=3537] smbd/negprot.c:404(reply_nt1)
using SPNEGO
[2011/05/10 19:29:03.067728, 3, pid=3537] smbd/negprot.c:691(reply_negprot)
Selected protocol NT LM 0.12
[2011/05/10 19:29:03.067739, 5, pid=3537] smbd/negprot.c:698(reply_negprot)
negprot index=5
[2011/05/10 19:29:03.067750, 5, pid=3537] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.067757, 5, pid=3537] lib/util.c:627(show_msg)
size=193
smb_com=0x72
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=136
smb_flg2=51283
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=0
smt_wct=17
smb_vwv[ 0]= 5 (0x5)
smb_vwv[ 1]=12803 (0x3203)
smb_vwv[ 2]= 256 (0x100)
smb_vwv[ 3]= 1024 (0x400)
smb_vwv[ 4]= 65 (0x41)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 256 (0x100)
smb_vwv[ 7]=53504 (0xD100)
smb_vwv[ 8]= 13 (0xD)
smb_vwv[ 9]=64768 (0xFD00)
smb_vwv[10]=33011 (0x80F3)
smb_vwv[11]=32896 (0x8080)
smb_vwv[12]= 3209 (0xC89)
smb_vwv[13]=27148 (0x6A0C)
smb_vwv[14]=52239 (0xCC0F)
smb_vwv[15]=61441 (0xF001)
smb_vwv[16]= 0 (0x0)
smb_bcc=124
[2011/05/10 19:29:03.067854, 10, pid=3537] ../lib/util/util.c:278(_dump_data)
[0000] 6E 70 73 6D 74 70 30 30 30 00 00 00 00 00 00 00 npsmtp00 0.......
[0010] 60 6A 06 06 2B 06 01 05 05 02 A0 60 30 5E A0 24 `j..+... ...`0^.$
[0020] 30 22 06 09 2A 86 48 86 F7 12 01 02 02 06 09 2A 0"..*.H. .......*
[0030] 86 48 82 F7 12 01 02 02 06 0A 2B 06 01 04 01 82 .H...... ..+.....
[0040] 37 02 02 0A A3 36 30 34 A0 32 1B 30 63 69 66 73 7....604 .2.0cifs
[0050] 2F 6E 70 73 6D 74 70 30 30 30 2E 6B 66 62 64 6F /npsmtp0 00.kfbdo
[0060] 6D 31 2E 6B 79 66 62 2E 70 72 69 40 4B 46 42 44 m1.kyfb. pri@KFBD
[0070] 4F 4D 31 2E 4B 59 46 42 2E 50 52 49 OM1.KYFB .PRI
[2011/05/10 19:29:03.069986, 10, pid=3537] lib/util_sock.c:731(read_smb_length_return_keepalive)
got smb length of 2026
[2011/05/10 19:29:03.070019, 6, pid=3537] smbd/process.c:1482(process_smb)
got message type 0x0 of len 0x7ea
[2011/05/10 19:29:03.070042, 3, pid=3537] smbd/process.c:1485(process_smb)
Transaction 1 of length 2030 (0 toread)
[2011/05/10 19:29:03.070057, 5, pid=3537] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.070064, 5, pid=3537] lib/util.c:627(show_msg)
size=2026
smb_com=0x73
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=64
smt_wct=12
smb_vwv[ 0]= 255 (0xFF)
smb_vwv[ 1]= 2026 (0x7EA)
smb_vwv[ 2]=16644 (0x4104)
smb_vwv[ 3]= 50 (0x32)
smb_vwv[ 4]= 0 (0x0)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 0 (0x0)
smb_vwv[ 7]= 1865 (0x749)
smb_vwv[ 8]= 0 (0x0)
smb_vwv[ 9]= 0 (0x0)
smb_vwv[10]= 212 (0xD4)
smb_vwv[11]=40960 (0xA000)
smb_bcc=1967
[2011/05/10 19:29:03.070136, 10, pid=3537] ../lib/util/util.c:278(_dump_data)
[0000] 60 82 07 45 06 06 2B 06 01 05 05 02 A0 82 07 39 `..E..+. .......9
[0010] 30 82 07 35 A0 24 30 22 06 09 2A 86 48 82 F7 12 0..5.$0" ..*.H...
[0020] 01 02 02 06 09 2A 86 48 86 F7 12 01 02 02 06 0A .....*.H ........
[0030] 2B 06 01 04 01 82 37 02 02 0A A2 82 07 0B 04 82 +.....7. ........
[0040] 07 07 60 82 07 03 06 09 2A 86 48 86 F7 12 01 02 ..`..... *.H.....
[0050] 02 01 00 6E 82 06 F2 30 82 06 EE A0 03 02 01 05 ...n...0 ........
[0060] A1 03 02 01 0E A2 07 03 05 00 20 00 00 00 A3 82 ........ .. .....
[0070] 06 13 61 82 06 0F 30 82 06 0B A0 03 02 01 05 A1 ..a...0. ........
[0080] 12 1B 10 4B 46 42 44 4F 4D 31 2E 4B 59 46 42 2E ...KFBDO M1.KYFB.
[0090] 50 52 49 A2 2D 30 2B A0 03 02 01 02 A1 24 30 22 PRI.-0+. .....$0"
[00A0] 1B 04 63 69 66 73 1B 1A 6E 70 73 6D 74 70 30 30 ..cifs.. npsmtp00
[00B0] 30 2E 6B 66 62 64 6F 6D 31 2E 6B 79 66 62 2E 70 0.kfbdom 1.kyfb.p
[00C0] 72 69 A3 82 05 BF 30 82 05 BB A0 03 02 01 17 A1 ri....0. ........
[00D0] 03 02 01 02 A2 82 05 AD 04 82 05 A9 74 19 2D 8F ........ ....t.-.
[00E0] 78 B2 BC 5A A7 C1 68 B8 EA 2C D4 00 DB F3 A0 E2 x..Z..h. .,......
[00F0] D6 42 62 FC 85 42 83 42 FF 9D 6E 49 31 51 81 A2 .Bb..B.B ..nI1Q..
[0100] 78 60 2B 3D D1 56 62 26 D4 D6 C2 77 38 B7 CD F8 x`+=.Vb& ...w8...
[0110] 7A 89 83 8E A9 D4 3C BB D7 1D C1 91 4D 89 17 A8 z.....<. ....M...
[0120] FE 57 E4 6E 75 F2 37 91 81 EF AA 3D 79 77 2F 39 .W.nu.7. ...=yw/9
[0130] A2 D8 2F C9 06 90 B0 03 61 5F 76 3C D3 79 65 03 ../..... a_v<.ye.
[0140] 68 91 0C 53 4F B1 62 20 27 03 81 D4 03 81 F8 FB h..SO.b '.......
[0150] 70 CC A7 20 5F 5D 3A 2B 40 6F 6F 41 1E 97 0D 2B p.. _]:+ @ooA...+
[0160] 95 8E 7E 6E D4 64 DC 14 C1 4F 1E B0 53 AB 63 AF ..~n.d.. .O..S.c.
[0170] 97 33 BB 91 DD 24 5D AA CD B2 99 6B DF 9F 54 33 .3...$]. ...k..T3
[0180] 57 8D 66 FC 66 98 03 5B 3F A4 C3 1A 05 83 B4 AA W.f.f..[ ?.......
[0190] 7E A7 FF D0 FF A0 D7 D7 53 6B 54 49 90 A6 AF 12 ~....... SkTI....
[01A0] 18 AD 2F 11 A4 16 43 12 5F A2 26 A3 77 88 AA DF ../...C. _.&.w...
[01B0] D1 B2 A8 2E 76 A9 10 9E 84 7A 8A DD 3D 3C 95 11 ....v... .z..=<..
[01C0] 44 FE 24 1D 10 95 51 10 EB 2B 27 38 69 AE 08 F5 D.$...Q. .+'8i...
[01D0] C2 4A 48 A7 D6 B0 A5 F2 DD 92 38 36 3D 6D 49 D0 .JH..... ..86=mI.
[01E0] EA C4 72 D2 FF 6E 13 59 C1 EA 43 13 D3 05 CF 50 ..r..n.Y ..C....P
[01F0] 85 B6 1E 6E BF 30 7A FF E8 35 CD 71 A1 DB AA AF ...n.0z. .5.q....
[2011/05/10 19:29:03.070556, 3, pid=3537] smbd/process.c:1294(switch_message)
switch message SMBsesssetupX (pid 3537) conn 0x0
[2011/05/10 19:29:03.070569, 3, pid=3537] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:03.070580, 5, pid=3537] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:03.070591, 5, pid=3537] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:03.070625, 5, pid=3537] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:03.070698, 3, pid=3537] smbd/sesssetup.c:1435(reply_sesssetup_and_X)
wct=12 flg2=0xc807
[2011/05/10 19:29:03.070717, 2, pid=3537] smbd/sesssetup.c:1390(setup_new_vc_session)
setup_new_vc_session: New VC == 0, if NT4.x compatible we would close all old resources.
[2011/05/10 19:29:03.070735, 3, pid=3537] smbd/sesssetup.c:1189(reply_sesssetup_and_X_spnego)
Doing spnego session setup
[2011/05/10 19:29:03.070761, 3, pid=3537] smbd/sesssetup.c:1231(reply_sesssetup_and_X_spnego)
NativeOS=[Windows 2002 Service Pack 3 2600] NativeLanMan=[Windows 2002 5.1] PrimaryDomain=[]
[2011/05/10 19:29:03.070775, 10, pid=3537] lib/util.c:1969(set_remote_arch)
set_remote_arch: Client arch is 'WinXP'
[2011/05/10 19:29:03.070795, 10, pid=3537] smbd/password.c:184(register_initial_vuid)
register_initial_vuid: allocated vuid = 100
[2011/05/10 19:29:03.070829, 10, pid=3537] smbd/sesssetup.c:1134(check_spnego_blob_complete)
check_spnego_blob_complete: needed_len = 1865, pblob->length = 1865
[2011/05/10 19:29:03.070895, 5, pid=3537] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.2.840.48018.1.2.2
[2011/05/10 19:29:03.070908, 5, pid=3537] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.2.840.113554.1.2.2
[2011/05/10 19:29:03.070919, 5, pid=3537] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.3.6.1.4.1.311.2.2.10
[2011/05/10 19:29:03.070929, 3, pid=3537] smbd/sesssetup.c:805(reply_spnego_negotiate)
reply_spnego_negotiate: Got secblob of size 1799
[2011/05/10 19:29:03.072080, 1, pid=3537] libads/kerberos_verify.c:339(ads_secrets_verify_ticket)
ads_secrets_verify_ticket: failed to fetch machine password
[2011/05/10 19:29:03.072118, 3, pid=3537] libads/kerberos_verify.c:589(ads_verify_ticket)
ads_verify_ticket: krb5_rd_req with auth failed (Cannot read password)
[2011/05/10 19:29:03.072143, 10, pid=3537] libads/kerberos_verify.c:598(ads_verify_ticket)
ads_verify_ticket: returning error NT_STATUS_LOGON_FAILURE
[2011/05/10 19:29:03.072193, 1, pid=3537] smbd/sesssetup.c:332(reply_spnego_kerberos)
Failed to verify incoming ticket with error NT_STATUS_LOGON_FAILURE!
[2011/05/10 19:29:03.072224, 3, pid=3537] smbd/error.c:80(error_packet_set)
error packet at smbd/sesssetup.c(334) cmd=115 (SMBsesssetupX) NT_STATUS_LOGON_FAILURE
[2011/05/10 19:29:03.072248, 5, pid=3537] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.072272, 5, pid=3537] lib/util.c:627(show_msg)
size=35
smb_com=0x73
smb_rcls=109
smb_reh=0
smb_err=49152
smb_flg=136
smb_flg2=51203
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=64
smt_wct=0
smb_bcc=0
[2011/05/10 19:29:03.073872, 10, pid=3537] lib/util_sock.c:731(read_smb_length_return_keepalive)
got smb length of 2026
[2011/05/10 19:29:03.073905, 6, pid=3537] smbd/process.c:1482(process_smb)
got message type 0x0 of len 0x7ea
[2011/05/10 19:29:03.073926, 3, pid=3537] smbd/process.c:1485(process_smb)
Transaction 2 of length 2030 (0 toread)
[2011/05/10 19:29:03.073948, 5, pid=3537] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.073966, 5, pid=3537] lib/util.c:627(show_msg)
size=2026
smb_com=0x73
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=128
smt_wct=12
smb_vwv[ 0]= 255 (0xFF)
smb_vwv[ 1]= 2026 (0x7EA)
smb_vwv[ 2]=16644 (0x4104)
smb_vwv[ 3]= 50 (0x32)
smb_vwv[ 4]= 0 (0x0)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 0 (0x0)
smb_vwv[ 7]= 1865 (0x749)
smb_vwv[ 8]= 0 (0x0)
smb_vwv[ 9]= 0 (0x0)
smb_vwv[10]= 212 (0xD4)
smb_vwv[11]=40960 (0xA000)
smb_bcc=1967
[2011/05/10 19:29:03.074043, 10, pid=3537] ../lib/util/util.c:278(_dump_data)
[0000] 60 82 07 45 06 06 2B 06 01 05 05 02 A0 82 07 39 `..E..+. .......9
[0010] 30 82 07 35 A0 24 30 22 06 09 2A 86 48 82 F7 12 0..5.$0" ..*.H...
[0020] 01 02 02 06 09 2A 86 48 86 F7 12 01 02 02 06 0A .....*.H ........
[0030] 2B 06 01 04 01 82 37 02 02 0A A2 82 07 0B 04 82 +.....7. ........
[0040] 07 07 60 82 07 03 06 09 2A 86 48 86 F7 12 01 02 ..`..... *.H.....
[0050] 02 01 00 6E 82 06 F2 30 82 06 EE A0 03 02 01 05 ...n...0 ........
[0060] A1 03 02 01 0E A2 07 03 05 00 20 00 00 00 A3 82 ........ .. .....
[0070] 06 13 61 82 06 0F 30 82 06 0B A0 03 02 01 05 A1 ..a...0. ........
[0080] 12 1B 10 4B 46 42 44 4F 4D 31 2E 4B 59 46 42 2E ...KFBDO M1.KYFB.
[0090] 50 52 49 A2 2D 30 2B A0 03 02 01 02 A1 24 30 22 PRI.-0+. .....$0"
[00A0] 1B 04 63 69 66 73 1B 1A 6E 70 73 6D 74 70 30 30 ..cifs.. npsmtp00
[00B0] 30 2E 6B 66 62 64 6F 6D 31 2E 6B 79 66 62 2E 70 0.kfbdom 1.kyfb.p
[00C0] 72 69 A3 82 05 BF 30 82 05 BB A0 03 02 01 17 A1 ri....0. ........
[00D0] 03 02 01 02 A2 82 05 AD 04 82 05 A9 74 19 2D 8F ........ ....t.-.
[00E0] 78 B2 BC 5A A7 C1 68 B8 EA 2C D4 00 DB F3 A0 E2 x..Z..h. .,......
[00F0] D6 42 62 FC 85 42 83 42 FF 9D 6E 49 31 51 81 A2 .Bb..B.B ..nI1Q..
[0100] 78 60 2B 3D D1 56 62 26 D4 D6 C2 77 38 B7 CD F8 x`+=.Vb& ...w8...
[0110] 7A 89 83 8E A9 D4 3C BB D7 1D C1 91 4D 89 17 A8 z.....<. ....M...
[0120] FE 57 E4 6E 75 F2 37 91 81 EF AA 3D 79 77 2F 39 .W.nu.7. ...=yw/9
[0130] A2 D8 2F C9 06 90 B0 03 61 5F 76 3C D3 79 65 03 ../..... a_v<.ye.
[0140] 68 91 0C 53 4F B1 62 20 27 03 81 D4 03 81 F8 FB h..SO.b '.......
[0150] 70 CC A7 20 5F 5D 3A 2B 40 6F 6F 41 1E 97 0D 2B p.. _]:+ @ooA...+
[0160] 95 8E 7E 6E D4 64 DC 14 C1 4F 1E B0 53 AB 63 AF ..~n.d.. .O..S.c.
[0170] 97 33 BB 91 DD 24 5D AA CD B2 99 6B DF 9F 54 33 .3...$]. ...k..T3
[0180] 57 8D 66 FC 66 98 03 5B 3F A4 C3 1A 05 83 B4 AA W.f.f..[ ?.......
[0190] 7E A7 FF D0 FF A0 D7 D7 53 6B 54 49 90 A6 AF 12 ~....... SkTI....
[01A0] 18 AD 2F 11 A4 16 43 12 5F A2 26 A3 77 88 AA DF ../...C. _.&.w...
[01B0] D1 B2 A8 2E 76 A9 10 9E 84 7A 8A DD 3D 3C 95 11 ....v... .z..=<..
[01C0] 44 FE 24 1D 10 95 51 10 EB 2B 27 38 69 AE 08 F5 D.$...Q. .+'8i...
[01D0] C2 4A 48 A7 D6 B0 A5 F2 DD 92 38 36 3D 6D 49 D0 .JH..... ..86=mI.
[01E0] EA C4 72 D2 FF 6E 13 59 C1 EA 43 13 D3 05 CF 50 ..r..n.Y ..C....P
[01F0] 85 B6 1E 6E BF 30 7A FF E8 35 CD 71 A1 DB AA AF ...n.0z. .5.q....
[2011/05/10 19:29:03.074438, 3, pid=3537] smbd/process.c:1294(switch_message)
switch message SMBsesssetupX (pid 3537) conn 0x0
[2011/05/10 19:29:03.074451, 3, pid=3537] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:03.074468, 5, pid=3537] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:03.074478, 5, pid=3537] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:03.074497, 5, pid=3537] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:03.074509, 3, pid=3537] smbd/sesssetup.c:1435(reply_sesssetup_and_X)
wct=12 flg2=0xc807
[2011/05/10 19:29:03.074520, 2, pid=3537] smbd/sesssetup.c:1390(setup_new_vc_session)
setup_new_vc_session: New VC == 0, if NT4.x compatible we would close all old resources.
[2011/05/10 19:29:03.074537, 3, pid=3537] smbd/sesssetup.c:1189(reply_sesssetup_and_X_spnego)
Doing spnego session setup
[2011/05/10 19:29:03.074551, 3, pid=3537] smbd/sesssetup.c:1231(reply_sesssetup_and_X_spnego)
NativeOS=[Windows 2002 Service Pack 3 2600] NativeLanMan=[Windows 2002 5.1] PrimaryDomain=[]
[2011/05/10 19:29:03.074563, 10, pid=3537] smbd/password.c:184(register_initial_vuid)
register_initial_vuid: allocated vuid = 101
[2011/05/10 19:29:03.074576, 10, pid=3537] smbd/sesssetup.c:1134(check_spnego_blob_complete)
check_spnego_blob_complete: needed_len = 1865, pblob->length = 1865
[2011/05/10 19:29:03.074603, 5, pid=3537] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.2.840.48018.1.2.2
[2011/05/10 19:29:03.074614, 5, pid=3537] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.2.840.113554.1.2.2
[2011/05/10 19:29:03.074624, 5, pid=3537] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.3.6.1.4.1.311.2.2.10
[2011/05/10 19:29:03.074634, 3, pid=3537] smbd/sesssetup.c:805(reply_spnego_negotiate)
reply_spnego_negotiate: Got secblob of size 1799
[2011/05/10 19:29:03.074859, 1, pid=3537] libads/kerberos_verify.c:339(ads_secrets_verify_ticket)
ads_secrets_verify_ticket: failed to fetch machine password
[2011/05/10 19:29:03.074885, 3, pid=3537] libads/kerberos_verify.c:589(ads_verify_ticket)
ads_verify_ticket: krb5_rd_req with auth failed (Cannot read password)
[2011/05/10 19:29:03.074898, 10, pid=3537] libads/kerberos_verify.c:598(ads_verify_ticket)
ads_verify_ticket: returning error NT_STATUS_LOGON_FAILURE
[2011/05/10 19:29:03.074913, 1, pid=3537] smbd/sesssetup.c:332(reply_spnego_kerberos)
Failed to verify incoming ticket with error NT_STATUS_LOGON_FAILURE!
[2011/05/10 19:29:03.074926, 3, pid=3537] smbd/error.c:80(error_packet_set)
error packet at smbd/sesssetup.c(334) cmd=115 (SMBsesssetupX) NT_STATUS_LOGON_FAILURE
[2011/05/10 19:29:03.074938, 5, pid=3537] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.074946, 5, pid=3537] lib/util.c:627(show_msg)
size=35
smb_com=0x73
smb_rcls=109
smb_reh=0
smb_err=49152
smb_flg=136
smb_flg2=51203
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=128
smt_wct=0
smb_bcc=0
[2011/05/10 19:29:03.075866, 5, pid=3537] lib/util_sock.c:462(read_fd_with_timeout)
read_fd_with_timeout: blocking read. EOF from client.
[2011/05/10 19:29:03.075896, 10, pid=3537] smbd/process.c:286(receive_smb_raw_talloc)
receive_smb_raw: NT_STATUS_END_OF_FILE
[2011/05/10 19:29:03.075918, 3, pid=3537] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:03.075943, 5, pid=3537] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:03.075954, 5, pid=3537] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:03.075971, 5, pid=3537] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:03.075993, 3, pid=3537] smbd/connection.c:31(yield_connection)
Yielding connection to
[2011/05/10 19:29:03.076038, 10, pid=3537] lib/dbwrap_tdb.c:100(db_tdb_fetch_locked)
Locking key D10D0000FFFFFFFFFFFF
[2011/05/10 19:29:03.076064, 10, pid=3537] lib/dbwrap_tdb.c:129(db_tdb_fetch_locked)
Allocated locked data 0x0x2b67a27c7d10
[2011/05/10 19:29:03.076085, 10, pid=3537] lib/dbwrap_tdb.c:42(db_tdb_record_destr)
Unlocking key D10D0000FFFFFFFFFFFF
[2011/05/10 19:29:03.076251, 3, pid=3537] smbd/server.c:902(exit_server_common)
Server exit (failed to receive smb request)
[2011/05/10 19:29:03.079719, 5, pid=3538] lib/util_sock.c:304(print_socket_options)
Socket options:
SO_KEEPALIVE = 1
SO_REUSEADDR = 1
SO_BROADCAST = 0
TCP_NODELAY = 1
TCP_KEEPCNT = 9
TCP_KEEPIDLE = 7200
TCP_KEEPINTVL = 75
IPTOS_LOWDELAY = 0
IPTOS_THROUGHPUT = 0
SO_SNDBUF = 16384
SO_RCVBUF = 87380
SO_SNDLOWAT = 1
SO_RCVLOWAT = 1
SO_SNDTIMEO = 0
SO_RCVTIMEO = 0
TCP_QUICKACK = 1
[2011/05/10 19:29:03.079992, 5, pid=3538] lib/util_sock.c:304(print_socket_options)
Socket options:
SO_KEEPALIVE = 1
SO_REUSEADDR = 1
SO_BROADCAST = 0
TCP_NODELAY = 1
TCP_KEEPCNT = 9
TCP_KEEPIDLE = 7200
TCP_KEEPINTVL = 75
IPTOS_LOWDELAY = 0
IPTOS_THROUGHPUT = 0
SO_SNDBUF = 16384
SO_RCVBUF = 87380
SO_SNDLOWAT = 1
SO_RCVLOWAT = 1
SO_SNDTIMEO = 0
SO_RCVTIMEO = 0
TCP_QUICKACK = 1
[2011/05/10 19:29:03.080674, 6, pid=3538] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:03.081165, 3, pid=3538] smbd/oplock.c:894(init_oplocks)
init_oplocks: initializing messages.
[2011/05/10 19:29:03.081309, 3, pid=3538] smbd/oplock_linux.c:224(linux_init_kernel_oplocks)
Linux kernel oplocks enabled
[2011/05/10 19:29:03.081330, 5, pid=3538] lib/messages.c:329(messaging_deregister)
Deregistering messaging pointer for type 1 - private_data=(nil)
[2011/05/10 19:29:03.081417, 10, pid=3538] smbd/process.c:740(event_add_idle)
event_add_idle: idle_evt(keepalive) 0x2b67a274f930
[2011/05/10 19:29:03.081437, 10, pid=3538] smbd/process.c:740(event_add_idle)
event_add_idle: idle_evt(deadtime) 0x2b67a2758220
[2011/05/10 19:29:03.081449, 10, pid=3538] smbd/process.c:740(event_add_idle)
event_add_idle: idle_evt(housekeeping) 0x2b67a27450e0
[2011/05/10 19:29:03.081529, 10, pid=3538] lib/util_sock.c:731(read_smb_length_return_keepalive)
got smb length of 133
[2011/05/10 19:29:03.081555, 6, pid=3538] smbd/process.c:1482(process_smb)
got message type 0x0 of len 0x85
[2011/05/10 19:29:03.081573, 3, pid=3538] smbd/process.c:1485(process_smb)
Transaction 0 of length 137 (0 toread)
[2011/05/10 19:29:03.081584, 5, pid=3538] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.081592, 5, pid=3538] lib/util.c:627(show_msg)
size=133
smb_com=0x72
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51283
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=0
smt_wct=0
smb_bcc=98
[2011/05/10 19:29:03.081630, 10, pid=3538] ../lib/util/util.c:278(_dump_data)
[0000] 02 50 43 20 4E 45 54 57 4F 52 4B 20 50 52 4F 47 .PC NETW ORK PROG
[0010] 52 41 4D 20 31 2E 30 00 02 4C 41 4E 4D 41 4E 31 RAM 1.0. .LANMAN1
[0020] 2E 30 00 02 57 69 6E 64 6F 77 73 20 66 6F 72 20 .0..Wind ows for
[0030] 57 6F 72 6B 67 72 6F 75 70 73 20 33 2E 31 61 00 Workgrou ps 3.1a.
[0040] 02 4C 4D 31 2E 32 58 30 30 32 00 02 4C 41 4E 4D .LM1.2X0 02..LANM
[0050] 41 4E 32 2E 31 00 02 4E 54 20 4C 4D 20 30 2E 31 AN2.1..N T LM 0.1
[0060] 32 00 2.
[2011/05/10 19:29:03.081763, 3, pid=3538] smbd/process.c:1294(switch_message)
switch message SMBnegprot (pid 3538) conn 0x0
[2011/05/10 19:29:03.081785, 3, pid=3538] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:03.081810, 5, pid=3538] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:03.081842, 5, pid=3538] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:03.081888, 5, pid=3538] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:03.082049, 3, pid=3538] smbd/negprot.c:586(reply_negprot)
Requested protocol [PC NETWORK PROGRAM 1.0]
[2011/05/10 19:29:03.082068, 3, pid=3538] smbd/negprot.c:586(reply_negprot)
Requested protocol [LANMAN1.0]
[2011/05/10 19:29:03.082080, 3, pid=3538] smbd/negprot.c:586(reply_negprot)
Requested protocol [Windows for Workgroups 3.1a]
[2011/05/10 19:29:03.082094, 3, pid=3538] smbd/negprot.c:586(reply_negprot)
Requested protocol [LM1.2X002]
[2011/05/10 19:29:03.082105, 3, pid=3538] smbd/negprot.c:586(reply_negprot)
Requested protocol [LANMAN2.1]
[2011/05/10 19:29:03.082115, 3, pid=3538] smbd/negprot.c:586(reply_negprot)
Requested protocol [NT LM 0.12]
[2011/05/10 19:29:03.082152, 10, pid=3538] lib/util.c:1969(set_remote_arch)
set_remote_arch: Client arch is 'Win2K'
[2011/05/10 19:29:03.082182, 6, pid=3538] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:03.082223, 5, pid=3538] smbd/connection.c:142(claim_connection)
claiming []
[2011/05/10 19:29:03.082282, 10, pid=3538] lib/dbwrap_tdb.c:100(db_tdb_fetch_locked)
Locking key D20D0000FFFFFFFFFFFF
[2011/05/10 19:29:03.082332, 10, pid=3538] lib/dbwrap_tdb.c:129(db_tdb_fetch_locked)
Allocated locked data 0x0x2b67a27e6f90
[2011/05/10 19:29:03.082399, 10, pid=3538] lib/dbwrap_tdb.c:42(db_tdb_record_destr)
Unlocking key D20D0000FFFFFFFFFFFF
[2011/05/10 19:29:03.082464, 6, pid=3538] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:03.082695, 10, pid=3538] lib/util.c:2598(name_to_fqdn)
name_to_fqdn: lookup for NPSMTP000 -> npsmtp000.child.root.pri.
[2011/05/10 19:29:03.082777, 3, pid=3538] smbd/negprot.c:404(reply_nt1)
using SPNEGO
[2011/05/10 19:29:03.082793, 3, pid=3538] smbd/negprot.c:691(reply_negprot)
Selected protocol NT LM 0.12
[2011/05/10 19:29:03.082804, 5, pid=3538] smbd/negprot.c:698(reply_negprot)
negprot index=5
[2011/05/10 19:29:03.082814, 5, pid=3538] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.082821, 5, pid=3538] lib/util.c:627(show_msg)
size=193
smb_com=0x72
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=136
smb_flg2=51283
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=0
smt_wct=17
smb_vwv[ 0]= 5 (0x5)
smb_vwv[ 1]=12803 (0x3203)
smb_vwv[ 2]= 256 (0x100)
smb_vwv[ 3]= 1024 (0x400)
smb_vwv[ 4]= 65 (0x41)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 256 (0x100)
smb_vwv[ 7]=53760 (0xD200)
smb_vwv[ 8]= 13 (0xD)
smb_vwv[ 9]=64768 (0xFD00)
smb_vwv[10]=33011 (0x80F3)
smb_vwv[11]=32896 (0x8080)
smb_vwv[12]= 3209 (0xC89)
smb_vwv[13]=27148 (0x6A0C)
smb_vwv[14]=52239 (0xCC0F)
smb_vwv[15]=61441 (0xF001)
smb_vwv[16]= 0 (0x0)
smb_bcc=124
[2011/05/10 19:29:03.082904, 10, pid=3538] ../lib/util/util.c:278(_dump_data)
[0000] 6E 70 73 6D 74 70 30 30 30 00 00 00 00 00 00 00 npsmtp00 0.......
[0010] 60 6A 06 06 2B 06 01 05 05 02 A0 60 30 5E A0 24 `j..+... ...`0^.$
[0020] 30 22 06 09 2A 86 48 86 F7 12 01 02 02 06 09 2A 0"..*.H. .......*
[0030] 86 48 82 F7 12 01 02 02 06 0A 2B 06 01 04 01 82 .H...... ..+.....
[0040] 37 02 02 0A A3 36 30 34 A0 32 1B 30 63 69 66 73 7....604 .2.0cifs
[0050] 2F 6E 70 73 6D 74 70 30 30 30 2E 6B 66 62 64 6F /npsmtp0 00.kfbdo
[0060] 6D 31 2E 6B 79 66 62 2E 70 72 69 40 4B 46 42 44 m1.kyfb. pri@KFBD
[0070] 4F 4D 31 2E 4B 59 46 42 2E 50 52 49 OM1.KYFB .PRI
[2011/05/10 19:29:03.083996, 10, pid=3538] lib/util_sock.c:731(read_smb_length_return_keepalive)
got smb length of 2026
[2011/05/10 19:29:03.084015, 6, pid=3538] smbd/process.c:1482(process_smb)
got message type 0x0 of len 0x7ea
[2011/05/10 19:29:03.084027, 3, pid=3538] smbd/process.c:1485(process_smb)
Transaction 1 of length 2030 (0 toread)
[2011/05/10 19:29:03.084038, 5, pid=3538] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.084045, 5, pid=3538] lib/util.c:627(show_msg)
size=2026
smb_com=0x73
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=64
smt_wct=12
smb_vwv[ 0]= 255 (0xFF)
smb_vwv[ 1]= 2026 (0x7EA)
smb_vwv[ 2]=16644 (0x4104)
smb_vwv[ 3]= 50 (0x32)
smb_vwv[ 4]= 0 (0x0)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 0 (0x0)
smb_vwv[ 7]= 1865 (0x749)
smb_vwv[ 8]= 0 (0x0)
smb_vwv[ 9]= 0 (0x0)
smb_vwv[10]= 212 (0xD4)
smb_vwv[11]=40960 (0xA000)
smb_bcc=1967
[2011/05/10 19:29:03.084116, 10, pid=3538] ../lib/util/util.c:278(_dump_data)
[0000] 60 82 07 45 06 06 2B 06 01 05 05 02 A0 82 07 39 `..E..+. .......9
[0010] 30 82 07 35 A0 24 30 22 06 09 2A 86 48 82 F7 12 0..5.$0" ..*.H...
[0020] 01 02 02 06 09 2A 86 48 86 F7 12 01 02 02 06 0A .....*.H ........
[0030] 2B 06 01 04 01 82 37 02 02 0A A2 82 07 0B 04 82 +.....7. ........
[0040] 07 07 60 82 07 03 06 09 2A 86 48 86 F7 12 01 02 ..`..... *.H.....
[0050] 02 01 00 6E 82 06 F2 30 82 06 EE A0 03 02 01 05 ...n...0 ........
[0060] A1 03 02 01 0E A2 07 03 05 00 20 00 00 00 A3 82 ........ .. .....
[0070] 06 13 61 82 06 0F 30 82 06 0B A0 03 02 01 05 A1 ..a...0. ........
[0080] 12 1B 10 4B 46 42 44 4F 4D 31 2E 4B 59 46 42 2E ...KFBDO M1.KYFB.
[0090] 50 52 49 A2 2D 30 2B A0 03 02 01 02 A1 24 30 22 PRI.-0+. .....$0"
[00A0] 1B 04 63 69 66 73 1B 1A 6E 70 73 6D 74 70 30 30 ..cifs.. npsmtp00
[00B0] 30 2E 6B 66 62 64 6F 6D 31 2E 6B 79 66 62 2E 70 0.kfbdom 1.kyfb.p
[00C0] 72 69 A3 82 05 BF 30 82 05 BB A0 03 02 01 17 A1 ri....0. ........
[00D0] 03 02 01 02 A2 82 05 AD 04 82 05 A9 74 19 2D 8F ........ ....t.-.
[00E0] 78 B2 BC 5A A7 C1 68 B8 EA 2C D4 00 DB F3 A0 E2 x..Z..h. .,......
[00F0] D6 42 62 FC 85 42 83 42 FF 9D 6E 49 31 51 81 A2 .Bb..B.B ..nI1Q..
[0100] 78 60 2B 3D D1 56 62 26 D4 D6 C2 77 38 B7 CD F8 x`+=.Vb& ...w8...
[0110] 7A 89 83 8E A9 D4 3C BB D7 1D C1 91 4D 89 17 A8 z.....<. ....M...
[0120] FE 57 E4 6E 75 F2 37 91 81 EF AA 3D 79 77 2F 39 .W.nu.7. ...=yw/9
[0130] A2 D8 2F C9 06 90 B0 03 61 5F 76 3C D3 79 65 03 ../..... a_v<.ye.
[0140] 68 91 0C 53 4F B1 62 20 27 03 81 D4 03 81 F8 FB h..SO.b '.......
[0150] 70 CC A7 20 5F 5D 3A 2B 40 6F 6F 41 1E 97 0D 2B p.. _]:+ @ooA...+
[0160] 95 8E 7E 6E D4 64 DC 14 C1 4F 1E B0 53 AB 63 AF ..~n.d.. .O..S.c.
[0170] 97 33 BB 91 DD 24 5D AA CD B2 99 6B DF 9F 54 33 .3...$]. ...k..T3
[0180] 57 8D 66 FC 66 98 03 5B 3F A4 C3 1A 05 83 B4 AA W.f.f..[ ?.......
[0190] 7E A7 FF D0 FF A0 D7 D7 53 6B 54 49 90 A6 AF 12 ~....... SkTI....
[01A0] 18 AD 2F 11 A4 16 43 12 5F A2 26 A3 77 88 AA DF ../...C. _.&.w...
[01B0] D1 B2 A8 2E 76 A9 10 9E 84 7A 8A DD 3D 3C 95 11 ....v... .z..=<..
[01C0] 44 FE 24 1D 10 95 51 10 EB 2B 27 38 69 AE 08 F5 D.$...Q. .+'8i...
[01D0] C2 4A 48 A7 D6 B0 A5 F2 DD 92 38 36 3D 6D 49 D0 .JH..... ..86=mI.
[01E0] EA C4 72 D2 FF 6E 13 59 C1 EA 43 13 D3 05 CF 50 ..r..n.Y ..C....P
[01F0] 85 B6 1E 6E BF 30 7A FF E8 35 CD 71 A1 DB AA AF ...n.0z. .5.q....
[2011/05/10 19:29:03.084514, 3, pid=3538] smbd/process.c:1294(switch_message)
switch message SMBsesssetupX (pid 3538) conn 0x0
[2011/05/10 19:29:03.084526, 3, pid=3538] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:03.084537, 5, pid=3538] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:03.084547, 5, pid=3538] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:03.084565, 5, pid=3538] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:03.084618, 3, pid=3538] smbd/sesssetup.c:1435(reply_sesssetup_and_X)
wct=12 flg2=0xc807
[2011/05/10 19:29:03.084640, 2, pid=3538] smbd/sesssetup.c:1390(setup_new_vc_session)
setup_new_vc_session: New VC == 0, if NT4.x compatible we would close all old resources.
[2011/05/10 19:29:03.084657, 3, pid=3538] smbd/sesssetup.c:1189(reply_sesssetup_and_X_spnego)
Doing spnego session setup
[2011/05/10 19:29:03.084680, 3, pid=3538] smbd/sesssetup.c:1231(reply_sesssetup_and_X_spnego)
NativeOS=[Windows 2002 Service Pack 3 2600] NativeLanMan=[Windows 2002 5.1] PrimaryDomain=[]
[2011/05/10 19:29:03.084693, 10, pid=3538] lib/util.c:1969(set_remote_arch)
set_remote_arch: Client arch is 'WinXP'
[2011/05/10 19:29:03.084711, 10, pid=3538] smbd/password.c:184(register_initial_vuid)
register_initial_vuid: allocated vuid = 100
[2011/05/10 19:29:03.084755, 10, pid=3538] smbd/sesssetup.c:1134(check_spnego_blob_complete)
check_spnego_blob_complete: needed_len = 1865, pblob->length = 1865
[2011/05/10 19:29:03.084830, 5, pid=3538] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.2.840.48018.1.2.2
[2011/05/10 19:29:03.084843, 5, pid=3538] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.2.840.113554.1.2.2
[2011/05/10 19:29:03.084853, 5, pid=3538] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.3.6.1.4.1.311.2.2.10
[2011/05/10 19:29:03.084863, 3, pid=3538] smbd/sesssetup.c:805(reply_spnego_negotiate)
reply_spnego_negotiate: Got secblob of size 1799
[2011/05/10 19:29:03.085974, 1, pid=3538] libads/kerberos_verify.c:339(ads_secrets_verify_ticket)
ads_secrets_verify_ticket: failed to fetch machine password
[2011/05/10 19:29:03.086013, 3, pid=3538] libads/kerberos_verify.c:589(ads_verify_ticket)
ads_verify_ticket: krb5_rd_req with auth failed (Cannot read password)
[2011/05/10 19:29:03.086038, 10, pid=3538] libads/kerberos_verify.c:598(ads_verify_ticket)
ads_verify_ticket: returning error NT_STATUS_LOGON_FAILURE
[2011/05/10 19:29:03.086087, 1, pid=3538] smbd/sesssetup.c:332(reply_spnego_kerberos)
Failed to verify incoming ticket with error NT_STATUS_LOGON_FAILURE!
[2011/05/10 19:29:03.086106, 3, pid=3538] smbd/error.c:80(error_packet_set)
error packet at smbd/sesssetup.c(334) cmd=115 (SMBsesssetupX) NT_STATUS_LOGON_FAILURE
[2011/05/10 19:29:03.086130, 5, pid=3538] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.086162, 5, pid=3538] lib/util.c:627(show_msg)
size=35
smb_com=0x73
smb_rcls=109
smb_reh=0
smb_err=49152
smb_flg=136
smb_flg2=51203
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=64
smt_wct=0
smb_bcc=0
[2011/05/10 19:29:03.110823, 5, pid=3538] lib/util_sock.c:462(read_fd_with_timeout)
read_fd_with_timeout: blocking read. EOF from client.
[2011/05/10 19:29:03.110916, 10, pid=3538] smbd/process.c:286(receive_smb_raw_talloc)
receive_smb_raw: NT_STATUS_END_OF_FILE
[2011/05/10 19:29:03.110934, 3, pid=3538] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:03.110949, 5, pid=3538] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:03.110961, 5, pid=3538] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:03.110994, 5, pid=3538] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:03.111027, 3, pid=3538] smbd/connection.c:31(yield_connection)
Yielding connection to
[2011/05/10 19:29:03.111124, 10, pid=3538] lib/dbwrap_tdb.c:100(db_tdb_fetch_locked)
Locking key D20D0000FFFFFFFFFFFF
[2011/05/10 19:29:03.111159, 10, pid=3538] lib/dbwrap_tdb.c:129(db_tdb_fetch_locked)
Allocated locked data 0x0x2b67a27c7d10
[2011/05/10 19:29:03.111183, 10, pid=3538] lib/dbwrap_tdb.c:42(db_tdb_record_destr)
Unlocking key D20D0000FFFFFFFFFFFF
[2011/05/10 19:29:03.114273, 5, pid=3539] lib/util_sock.c:304(print_socket_options)
Socket options:
SO_KEEPALIVE = 1
SO_REUSEADDR = 1
SO_BROADCAST = 0
TCP_NODELAY = 1
TCP_KEEPCNT = 9
TCP_KEEPIDLE = 7200
TCP_KEEPINTVL = 75
IPTOS_LOWDELAY = 0
IPTOS_THROUGHPUT = 0
SO_SNDBUF = 16384
SO_RCVBUF = 87380
SO_SNDLOWAT = 1
SO_RCVLOWAT = 1
SO_SNDTIMEO = 0
SO_RCVTIMEO = 0
TCP_QUICKACK = 1
[2011/05/10 19:29:03.114512, 5, pid=3539] lib/util_sock.c:304(print_socket_options)
Socket options:
SO_KEEPALIVE = 1
SO_REUSEADDR = 1
SO_BROADCAST = 0
TCP_NODELAY = 1
TCP_KEEPCNT = 9
TCP_KEEPIDLE = 7200
TCP_KEEPINTVL = 75
IPTOS_LOWDELAY = 0
IPTOS_THROUGHPUT = 0
SO_SNDBUF = 16384
SO_RCVBUF = 87380
SO_SNDLOWAT = 1
SO_RCVLOWAT = 1
SO_SNDTIMEO = 0
SO_RCVTIMEO = 0
TCP_QUICKACK = 1
[2011/05/10 19:29:03.115086, 6, pid=3539] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:03.115548, 3, pid=3539] smbd/oplock.c:894(init_oplocks)
init_oplocks: initializing messages.
[2011/05/10 19:29:03.115706, 3, pid=3539] smbd/oplock_linux.c:224(linux_init_kernel_oplocks)
Linux kernel oplocks enabled
[2011/05/10 19:29:03.115725, 5, pid=3539] lib/messages.c:329(messaging_deregister)
Deregistering messaging pointer for type 1 - private_data=(nil)
[2011/05/10 19:29:03.115788, 10, pid=3539] smbd/process.c:740(event_add_idle)
event_add_idle: idle_evt(keepalive) 0x2b67a274f930
[2011/05/10 19:29:03.115807, 10, pid=3539] smbd/process.c:740(event_add_idle)
event_add_idle: idle_evt(deadtime) 0x2b67a2758220
[2011/05/10 19:29:03.115820, 10, pid=3539] smbd/process.c:740(event_add_idle)
event_add_idle: idle_evt(housekeeping) 0x2b67a27450e0
[2011/05/10 19:29:03.115899, 10, pid=3539] lib/util_sock.c:731(read_smb_length_return_keepalive)
got smb length of 133
[2011/05/10 19:29:03.115930, 6, pid=3539] smbd/process.c:1482(process_smb)
got message type 0x0 of len 0x85
[2011/05/10 19:29:03.115948, 3, pid=3539] smbd/process.c:1485(process_smb)
Transaction 0 of length 137 (0 toread)
[2011/05/10 19:29:03.115962, 5, pid=3539] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.115969, 5, pid=3539] lib/util.c:627(show_msg)
size=133
smb_com=0x72
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51283
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=0
smt_wct=0
smb_bcc=98
[2011/05/10 19:29:03.116009, 10, pid=3539] ../lib/util/util.c:278(_dump_data)
[0000] 02 50 43 20 4E 45 54 57 4F 52 4B 20 50 52 4F 47 .PC NETW ORK PROG
[0010] 52 41 4D 20 31 2E 30 00 02 4C 41 4E 4D 41 4E 31 RAM 1.0. .LANMAN1
[0020] 2E 30 00 02 57 69 6E 64 6F 77 73 20 66 6F 72 20 .0..Wind ows for
[0030] 57 6F 72 6B 67 72 6F 75 70 73 20 33 2E 31 61 00 Workgrou ps 3.1a.
[0040] 02 4C 4D 31 2E 32 58 30 30 32 00 02 4C 41 4E 4D .LM1.2X0 02..LANM
[0050] 41 4E 32 2E 31 00 02 4E 54 20 4C 4D 20 30 2E 31 AN2.1..N T LM 0.1
[0060] 32 00 2.
[2011/05/10 19:29:03.116126, 3, pid=3539] smbd/process.c:1294(switch_message)
switch message SMBnegprot (pid 3539) conn 0x0
[2011/05/10 19:29:03.116147, 3, pid=3539] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:03.116172, 5, pid=3539] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:03.116207, 5, pid=3539] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:03.116260, 5, pid=3539] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:03.116433, 3, pid=3539] smbd/negprot.c:586(reply_negprot)
Requested protocol [PC NETWORK PROGRAM 1.0]
[2011/05/10 19:29:03.116455, 3, pid=3539] smbd/negprot.c:586(reply_negprot)
Requested protocol [LANMAN1.0]
[2011/05/10 19:29:03.116468, 3, pid=3539] smbd/negprot.c:586(reply_negprot)
Requested protocol [Windows for Workgroups 3.1a]
[2011/05/10 19:29:03.116481, 3, pid=3539] smbd/negprot.c:586(reply_negprot)
Requested protocol [LM1.2X002]
[2011/05/10 19:29:03.116492, 3, pid=3539] smbd/negprot.c:586(reply_negprot)
Requested protocol [LANMAN2.1]
[2011/05/10 19:29:03.116504, 3, pid=3539] smbd/negprot.c:586(reply_negprot)
Requested protocol [NT LM 0.12]
[2011/05/10 19:29:03.116528, 10, pid=3539] lib/util.c:1969(set_remote_arch)
set_remote_arch: Client arch is 'Win2K'
[2011/05/10 19:29:03.116554, 6, pid=3539] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:03.116582, 5, pid=3539] smbd/connection.c:142(claim_connection)
claiming []
[2011/05/10 19:29:03.116645, 10, pid=3539] lib/dbwrap_tdb.c:100(db_tdb_fetch_locked)
Locking key D30D0000FFFFFFFFFFFF
[2011/05/10 19:29:03.116694, 10, pid=3539] lib/dbwrap_tdb.c:129(db_tdb_fetch_locked)
Allocated locked data 0x0x2b67a27e6f90
[2011/05/10 19:29:03.116765, 10, pid=3539] lib/dbwrap_tdb.c:42(db_tdb_record_destr)
Unlocking key D30D0000FFFFFFFFFFFF
[2011/05/10 19:29:03.116838, 6, pid=3539] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:03.117053, 10, pid=3539] lib/util.c:2598(name_to_fqdn)
name_to_fqdn: lookup for NPSMTP000 -> npsmtp000.child.root.pri.
[2011/05/10 19:29:03.117138, 3, pid=3539] smbd/negprot.c:404(reply_nt1)
using SPNEGO
[2011/05/10 19:29:03.117155, 3, pid=3539] smbd/negprot.c:691(reply_negprot)
Selected protocol NT LM 0.12
[2011/05/10 19:29:03.117166, 5, pid=3539] smbd/negprot.c:698(reply_negprot)
negprot index=5
[2011/05/10 19:29:03.117177, 5, pid=3539] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.117184, 5, pid=3539] lib/util.c:627(show_msg)
size=193
smb_com=0x72
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=136
smb_flg2=51283
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=0
smt_wct=17
smb_vwv[ 0]= 5 (0x5)
smb_vwv[ 1]=12803 (0x3203)
smb_vwv[ 2]= 256 (0x100)
smb_vwv[ 3]= 1024 (0x400)
smb_vwv[ 4]= 65 (0x41)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 256 (0x100)
smb_vwv[ 7]=54016 (0xD300)
smb_vwv[ 8]= 13 (0xD)
smb_vwv[ 9]=64768 (0xFD00)
smb_vwv[10]=33011 (0x80F3)
smb_vwv[11]=32896 (0x8080)
smb_vwv[12]= 3209 (0xC89)
smb_vwv[13]=27148 (0x6A0C)
smb_vwv[14]=52239 (0xCC0F)
smb_vwv[15]=61441 (0xF001)
smb_vwv[16]= 0 (0x0)
smb_bcc=124
[2011/05/10 19:29:03.117294, 10, pid=3539] ../lib/util/util.c:278(_dump_data)
[0000] 6E 70 73 6D 74 70 30 30 30 00 00 00 00 00 00 00 npsmtp00 0.......
[0010] 60 6A 06 06 2B 06 01 05 05 02 A0 60 30 5E A0 24 `j..+... ...`0^.$
[0020] 30 22 06 09 2A 86 48 86 F7 12 01 02 02 06 09 2A 0"..*.H. .......*
[0030] 86 48 82 F7 12 01 02 02 06 0A 2B 06 01 04 01 82 .H...... ..+.....
[0040] 37 02 02 0A A3 36 30 34 A0 32 1B 30 63 69 66 73 7....604 .2.0cifs
[0050] 2F 6E 70 73 6D 74 70 30 30 30 2E 6B 66 62 64 6F /npsmtp0 00.kfbdo
[0060] 6D 31 2E 6B 79 66 62 2E 70 72 69 40 4B 46 42 44 m1.kyfb. pri@KFBD
[0070] 4F 4D 31 2E 4B 59 46 42 2E 50 52 49 OM1.KYFB .PRI
[2011/05/10 19:29:03.117597, 3, pid=3538] smbd/server.c:902(exit_server_common)
Server exit (failed to receive smb request)
[2011/05/10 19:29:03.122917, 10, pid=3539] lib/util_sock.c:731(read_smb_length_return_keepalive)
got smb length of 2026
[2011/05/10 19:29:03.122974, 6, pid=3539] smbd/process.c:1482(process_smb)
got message type 0x0 of len 0x7ea
[2011/05/10 19:29:03.122986, 3, pid=3539] smbd/process.c:1485(process_smb)
Transaction 1 of length 2030 (0 toread)
[2011/05/10 19:29:03.122997, 5, pid=3539] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.123005, 5, pid=3539] lib/util.c:627(show_msg)
size=2026
smb_com=0x73
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=64
smt_wct=12
smb_vwv[ 0]= 255 (0xFF)
smb_vwv[ 1]= 2026 (0x7EA)
smb_vwv[ 2]=16644 (0x4104)
smb_vwv[ 3]= 50 (0x32)
smb_vwv[ 4]= 0 (0x0)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 0 (0x0)
smb_vwv[ 7]= 1865 (0x749)
smb_vwv[ 8]= 0 (0x0)
smb_vwv[ 9]= 0 (0x0)
smb_vwv[10]= 212 (0xD4)
smb_vwv[11]=40960 (0xA000)
smb_bcc=1967
[2011/05/10 19:29:03.123084, 10, pid=3539] ../lib/util/util.c:278(_dump_data)
[0000] 60 82 07 45 06 06 2B 06 01 05 05 02 A0 82 07 39 `..E..+. .......9
[0010] 30 82 07 35 A0 24 30 22 06 09 2A 86 48 82 F7 12 0..5.$0" ..*.H...
[0020] 01 02 02 06 09 2A 86 48 86 F7 12 01 02 02 06 0A .....*.H ........
[0030] 2B 06 01 04 01 82 37 02 02 0A A2 82 07 0B 04 82 +.....7. ........
[0040] 07 07 60 82 07 03 06 09 2A 86 48 86 F7 12 01 02 ..`..... *.H.....
[0050] 02 01 00 6E 82 06 F2 30 82 06 EE A0 03 02 01 05 ...n...0 ........
[0060] A1 03 02 01 0E A2 07 03 05 00 20 00 00 00 A3 82 ........ .. .....
[0070] 06 13 61 82 06 0F 30 82 06 0B A0 03 02 01 05 A1 ..a...0. ........
[0080] 12 1B 10 4B 46 42 44 4F 4D 31 2E 4B 59 46 42 2E ...KFBDO M1.KYFB.
[0090] 50 52 49 A2 2D 30 2B A0 03 02 01 02 A1 24 30 22 PRI.-0+. .....$0"
[00A0] 1B 04 63 69 66 73 1B 1A 6E 70 73 6D 74 70 30 30 ..cifs.. npsmtp00
[00B0] 30 2E 6B 66 62 64 6F 6D 31 2E 6B 79 66 62 2E 70 0.kfbdom 1.kyfb.p
[00C0] 72 69 A3 82 05 BF 30 82 05 BB A0 03 02 01 17 A1 ri....0. ........
[00D0] 03 02 01 02 A2 82 05 AD 04 82 05 A9 74 19 2D 8F ........ ....t.-.
[00E0] 78 B2 BC 5A A7 C1 68 B8 EA 2C D4 00 DB F3 A0 E2 x..Z..h. .,......
[00F0] D6 42 62 FC 85 42 83 42 FF 9D 6E 49 31 51 81 A2 .Bb..B.B ..nI1Q..
[0100] 78 60 2B 3D D1 56 62 26 D4 D6 C2 77 38 B7 CD F8 x`+=.Vb& ...w8...
[0110] 7A 89 83 8E A9 D4 3C BB D7 1D C1 91 4D 89 17 A8 z.....<. ....M...
[0120] FE 57 E4 6E 75 F2 37 91 81 EF AA 3D 79 77 2F 39 .W.nu.7. ...=yw/9
[0130] A2 D8 2F C9 06 90 B0 03 61 5F 76 3C D3 79 65 03 ../..... a_v<.ye.
[0140] 68 91 0C 53 4F B1 62 20 27 03 81 D4 03 81 F8 FB h..SO.b '.......
[0150] 70 CC A7 20 5F 5D 3A 2B 40 6F 6F 41 1E 97 0D 2B p.. _]:+ @ooA...+
[0160] 95 8E 7E 6E D4 64 DC 14 C1 4F 1E B0 53 AB 63 AF ..~n.d.. .O..S.c.
[0170] 97 33 BB 91 DD 24 5D AA CD B2 99 6B DF 9F 54 33 .3...$]. ...k..T3
[0180] 57 8D 66 FC 66 98 03 5B 3F A4 C3 1A 05 83 B4 AA W.f.f..[ ?.......
[0190] 7E A7 FF D0 FF A0 D7 D7 53 6B 54 49 90 A6 AF 12 ~....... SkTI....
[01A0] 18 AD 2F 11 A4 16 43 12 5F A2 26 A3 77 88 AA DF ../...C. _.&.w...
[01B0] D1 B2 A8 2E 76 A9 10 9E 84 7A 8A DD 3D 3C 95 11 ....v... .z..=<..
[01C0] 44 FE 24 1D 10 95 51 10 EB 2B 27 38 69 AE 08 F5 D.$...Q. .+'8i...
[01D0] C2 4A 48 A7 D6 B0 A5 F2 DD 92 38 36 3D 6D 49 D0 .JH..... ..86=mI.
[01E0] EA C4 72 D2 FF 6E 13 59 C1 EA 43 13 D3 05 CF 50 ..r..n.Y ..C....P
[01F0] 85 B6 1E 6E BF 30 7A FF E8 35 CD 71 A1 DB AA AF ...n.0z. .5.q....
[2011/05/10 19:29:03.123571, 3, pid=3539] smbd/process.c:1294(switch_message)
switch message SMBsesssetupX (pid 3539) conn 0x0
[2011/05/10 19:29:03.123585, 3, pid=3539] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:03.123597, 5, pid=3539] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:03.123608, 5, pid=3539] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:03.123633, 5, pid=3539] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:03.123697, 3, pid=3539] smbd/sesssetup.c:1435(reply_sesssetup_and_X)
wct=12 flg2=0xc807
[2011/05/10 19:29:03.123721, 2, pid=3539] smbd/sesssetup.c:1390(setup_new_vc_session)
setup_new_vc_session: New VC == 0, if NT4.x compatible we would close all old resources.
[2011/05/10 19:29:03.123738, 3, pid=3539] smbd/sesssetup.c:1189(reply_sesssetup_and_X_spnego)
Doing spnego session setup
[2011/05/10 19:29:03.123768, 3, pid=3539] smbd/sesssetup.c:1231(reply_sesssetup_and_X_spnego)
NativeOS=[Windows 2002 Service Pack 3 2600] NativeLanMan=[Windows 2002 5.1] PrimaryDomain=[]
[2011/05/10 19:29:03.123781, 10, pid=3539] lib/util.c:1969(set_remote_arch)
set_remote_arch: Client arch is 'WinXP'
[2011/05/10 19:29:03.123801, 10, pid=3539] smbd/password.c:184(register_initial_vuid)
register_initial_vuid: allocated vuid = 100
[2011/05/10 19:29:03.123839, 10, pid=3539] smbd/sesssetup.c:1134(check_spnego_blob_complete)
check_spnego_blob_complete: needed_len = 1865, pblob->length = 1865
[2011/05/10 19:29:03.123913, 5, pid=3539] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.2.840.48018.1.2.2
[2011/05/10 19:29:03.123926, 5, pid=3539] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.2.840.113554.1.2.2
[2011/05/10 19:29:03.123937, 5, pid=3539] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.3.6.1.4.1.311.2.2.10
[2011/05/10 19:29:03.123947, 3, pid=3539] smbd/sesssetup.c:805(reply_spnego_negotiate)
reply_spnego_negotiate: Got secblob of size 1799
[2011/05/10 19:29:03.125228, 1, pid=3539] libads/kerberos_verify.c:339(ads_secrets_verify_ticket)
ads_secrets_verify_ticket: failed to fetch machine password
[2011/05/10 19:29:03.125291, 3, pid=3539] libads/kerberos_verify.c:589(ads_verify_ticket)
ads_verify_ticket: krb5_rd_req with auth failed (Cannot read password)
[2011/05/10 19:29:03.125316, 10, pid=3539] libads/kerberos_verify.c:598(ads_verify_ticket)
ads_verify_ticket: returning error NT_STATUS_LOGON_FAILURE
[2011/05/10 19:29:03.125380, 1, pid=3539] smbd/sesssetup.c:332(reply_spnego_kerberos)
Failed to verify incoming ticket with error NT_STATUS_LOGON_FAILURE!
[2011/05/10 19:29:03.125401, 3, pid=3539] smbd/error.c:80(error_packet_set)
error packet at smbd/sesssetup.c(334) cmd=115 (SMBsesssetupX) NT_STATUS_LOGON_FAILURE
[2011/05/10 19:29:03.125426, 5, pid=3539] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.125455, 5, pid=3539] lib/util.c:627(show_msg)
size=35
smb_com=0x73
smb_rcls=109
smb_reh=0
smb_err=49152
smb_flg=136
smb_flg2=51203
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=64
smt_wct=0
smb_bcc=0
[2011/05/10 19:29:03.127271, 10, pid=3539] lib/util_sock.c:731(read_smb_length_return_keepalive)
got smb length of 2026
[2011/05/10 19:29:03.127290, 6, pid=3539] smbd/process.c:1482(process_smb)
got message type 0x0 of len 0x7ea
[2011/05/10 19:29:03.127301, 3, pid=3539] smbd/process.c:1485(process_smb)
Transaction 2 of length 2030 (0 toread)
[2011/05/10 19:29:03.127312, 5, pid=3539] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.127319, 5, pid=3539] lib/util.c:627(show_msg)
size=2026
smb_com=0x73
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=128
smt_wct=12
smb_vwv[ 0]= 255 (0xFF)
smb_vwv[ 1]= 2026 (0x7EA)
smb_vwv[ 2]=16644 (0x4104)
smb_vwv[ 3]= 50 (0x32)
smb_vwv[ 4]= 0 (0x0)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 0 (0x0)
smb_vwv[ 7]= 1865 (0x749)
smb_vwv[ 8]= 0 (0x0)
smb_vwv[ 9]= 0 (0x0)
smb_vwv[10]= 212 (0xD4)
smb_vwv[11]=40960 (0xA000)
smb_bcc=1967
[2011/05/10 19:29:03.127432, 10, pid=3539] ../lib/util/util.c:278(_dump_data)
[0000] 60 82 07 45 06 06 2B 06 01 05 05 02 A0 82 07 39 `..E..+. .......9
[0010] 30 82 07 35 A0 24 30 22 06 09 2A 86 48 82 F7 12 0..5.$0" ..*.H...
[0020] 01 02 02 06 09 2A 86 48 86 F7 12 01 02 02 06 0A .....*.H ........
[0030] 2B 06 01 04 01 82 37 02 02 0A A2 82 07 0B 04 82 +.....7. ........
[0040] 07 07 60 82 07 03 06 09 2A 86 48 86 F7 12 01 02 ..`..... *.H.....
[0050] 02 01 00 6E 82 06 F2 30 82 06 EE A0 03 02 01 05 ...n...0 ........
[0060] A1 03 02 01 0E A2 07 03 05 00 20 00 00 00 A3 82 ........ .. .....
[0070] 06 13 61 82 06 0F 30 82 06 0B A0 03 02 01 05 A1 ..a...0. ........
[0080] 12 1B 10 4B 46 42 44 4F 4D 31 2E 4B 59 46 42 2E ...KFBDO M1.KYFB.
[0090] 50 52 49 A2 2D 30 2B A0 03 02 01 02 A1 24 30 22 PRI.-0+. .....$0"
[00A0] 1B 04 63 69 66 73 1B 1A 6E 70 73 6D 74 70 30 30 ..cifs.. npsmtp00
[00B0] 30 2E 6B 66 62 64 6F 6D 31 2E 6B 79 66 62 2E 70 0.kfbdom 1.kyfb.p
[00C0] 72 69 A3 82 05 BF 30 82 05 BB A0 03 02 01 17 A1 ri....0. ........
[00D0] 03 02 01 02 A2 82 05 AD 04 82 05 A9 74 19 2D 8F ........ ....t.-.
[00E0] 78 B2 BC 5A A7 C1 68 B8 EA 2C D4 00 DB F3 A0 E2 x..Z..h. .,......
[00F0] D6 42 62 FC 85 42 83 42 FF 9D 6E 49 31 51 81 A2 .Bb..B.B ..nI1Q..
[0100] 78 60 2B 3D D1 56 62 26 D4 D6 C2 77 38 B7 CD F8 x`+=.Vb& ...w8...
[0110] 7A 89 83 8E A9 D4 3C BB D7 1D C1 91 4D 89 17 A8 z.....<. ....M...
[0120] FE 57 E4 6E 75 F2 37 91 81 EF AA 3D 79 77 2F 39 .W.nu.7. ...=yw/9
[0130] A2 D8 2F C9 06 90 B0 03 61 5F 76 3C D3 79 65 03 ../..... a_v<.ye.
[0140] 68 91 0C 53 4F B1 62 20 27 03 81 D4 03 81 F8 FB h..SO.b '.......
[0150] 70 CC A7 20 5F 5D 3A 2B 40 6F 6F 41 1E 97 0D 2B p.. _]:+ @ooA...+
[0160] 95 8E 7E 6E D4 64 DC 14 C1 4F 1E B0 53 AB 63 AF ..~n.d.. .O..S.c.
[0170] 97 33 BB 91 DD 24 5D AA CD B2 99 6B DF 9F 54 33 .3...$]. ...k..T3
[0180] 57 8D 66 FC 66 98 03 5B 3F A4 C3 1A 05 83 B4 AA W.f.f..[ ?.......
[0190] 7E A7 FF D0 FF A0 D7 D7 53 6B 54 49 90 A6 AF 12 ~....... SkTI....
[01A0] 18 AD 2F 11 A4 16 43 12 5F A2 26 A3 77 88 AA DF ../...C. _.&.w...
[01B0] D1 B2 A8 2E 76 A9 10 9E 84 7A 8A DD 3D 3C 95 11 ....v... .z..=<..
[01C0] 44 FE 24 1D 10 95 51 10 EB 2B 27 38 69 AE 08 F5 D.$...Q. .+'8i...
[01D0] C2 4A 48 A7 D6 B0 A5 F2 DD 92 38 36 3D 6D 49 D0 .JH..... ..86=mI.
[01E0] EA C4 72 D2 FF 6E 13 59 C1 EA 43 13 D3 05 CF 50 ..r..n.Y ..C....P
[01F0] 85 B6 1E 6E BF 30 7A FF E8 35 CD 71 A1 DB AA AF ...n.0z. .5.q....
[2011/05/10 19:29:03.127803, 3, pid=3539] smbd/process.c:1294(switch_message)
switch message SMBsesssetupX (pid 3539) conn 0x0
[2011/05/10 19:29:03.127816, 3, pid=3539] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:03.127827, 5, pid=3539] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:03.127837, 5, pid=3539] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:03.127855, 5, pid=3539] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:03.127868, 3, pid=3539] smbd/sesssetup.c:1435(reply_sesssetup_and_X)
wct=12 flg2=0xc807
[2011/05/10 19:29:03.127878, 2, pid=3539] smbd/sesssetup.c:1390(setup_new_vc_session)
setup_new_vc_session: New VC == 0, if NT4.x compatible we would close all old resources.
[2011/05/10 19:29:03.127889, 3, pid=3539] smbd/sesssetup.c:1189(reply_sesssetup_and_X_spnego)
Doing spnego session setup
[2011/05/10 19:29:03.127902, 3, pid=3539] smbd/sesssetup.c:1231(reply_sesssetup_and_X_spnego)
NativeOS=[Windows 2002 Service Pack 3 2600] NativeLanMan=[Windows 2002 5.1] PrimaryDomain=[]
[2011/05/10 19:29:03.127914, 10, pid=3539] smbd/password.c:184(register_initial_vuid)
register_initial_vuid: allocated vuid = 101
[2011/05/10 19:29:03.127927, 10, pid=3539] smbd/sesssetup.c:1134(check_spnego_blob_complete)
check_spnego_blob_complete: needed_len = 1865, pblob->length = 1865
[2011/05/10 19:29:03.127955, 5, pid=3539] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.2.840.48018.1.2.2
[2011/05/10 19:29:03.127967, 5, pid=3539] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.2.840.113554.1.2.2
[2011/05/10 19:29:03.127977, 5, pid=3539] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.3.6.1.4.1.311.2.2.10
[2011/05/10 19:29:03.127987, 3, pid=3539] smbd/sesssetup.c:805(reply_spnego_negotiate)
reply_spnego_negotiate: Got secblob of size 1799
[2011/05/10 19:29:03.128217, 1, pid=3539] libads/kerberos_verify.c:339(ads_secrets_verify_ticket)
ads_secrets_verify_ticket: failed to fetch machine password
[2011/05/10 19:29:03.128244, 3, pid=3539] libads/kerberos_verify.c:589(ads_verify_ticket)
ads_verify_ticket: krb5_rd_req with auth failed (Cannot read password)
[2011/05/10 19:29:03.128256, 10, pid=3539] libads/kerberos_verify.c:598(ads_verify_ticket)
ads_verify_ticket: returning error NT_STATUS_LOGON_FAILURE
[2011/05/10 19:29:03.128273, 1, pid=3539] smbd/sesssetup.c:332(reply_spnego_kerberos)
Failed to verify incoming ticket with error NT_STATUS_LOGON_FAILURE!
[2011/05/10 19:29:03.128286, 3, pid=3539] smbd/error.c:80(error_packet_set)
error packet at smbd/sesssetup.c(334) cmd=115 (SMBsesssetupX) NT_STATUS_LOGON_FAILURE
[2011/05/10 19:29:03.128298, 5, pid=3539] lib/util.c:617(show_msg)
[2011/05/10 19:29:03.128305, 5, pid=3539] lib/util.c:627(show_msg)
size=35
smb_com=0x73
smb_rcls=109
smb_reh=0
smb_err=49152
smb_flg=136
smb_flg2=51203
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=128
smt_wct=0
smb_bcc=0
[2011/05/10 19:29:03.139101, 5, pid=3539] lib/util_sock.c:462(read_fd_with_timeout)
read_fd_with_timeout: blocking read. EOF from client.
[2011/05/10 19:29:03.139138, 10, pid=3539] smbd/process.c:286(receive_smb_raw_talloc)
receive_smb_raw: NT_STATUS_END_OF_FILE
[2011/05/10 19:29:03.139159, 3, pid=3539] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:03.139215, 5, pid=3539] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:03.139241, 5, pid=3539] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:03.139260, 5, pid=3539] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:03.139286, 3, pid=3539] smbd/connection.c:31(yield_connection)
Yielding connection to
[2011/05/10 19:29:03.139332, 10, pid=3539] lib/dbwrap_tdb.c:100(db_tdb_fetch_locked)
Locking key D30D0000FFFFFFFFFFFF
[2011/05/10 19:29:03.139355, 10, pid=3539] lib/dbwrap_tdb.c:129(db_tdb_fetch_locked)
Allocated locked data 0x0x2b67a27c7d10
[2011/05/10 19:29:03.139374, 10, pid=3539] lib/dbwrap_tdb.c:42(db_tdb_record_destr)
Unlocking key D30D0000FFFFFFFFFFFF
[2011/05/10 19:29:03.139528, 3, pid=3539] smbd/server.c:902(exit_server_common)
Server exit (failed to receive smb request)
[2011/05/10 19:29:07.842090, 5, pid=3540] lib/util_sock.c:304(print_socket_options)
Socket options:
SO_KEEPALIVE = 1
SO_REUSEADDR = 1
SO_BROADCAST = 0
TCP_NODELAY = 1
TCP_KEEPCNT = 9
TCP_KEEPIDLE = 7200
TCP_KEEPINTVL = 75
IPTOS_LOWDELAY = 0
IPTOS_THROUGHPUT = 0
SO_SNDBUF = 16384
SO_RCVBUF = 87380
SO_SNDLOWAT = 1
SO_RCVLOWAT = 1
SO_SNDTIMEO = 0
SO_RCVTIMEO = 0
TCP_QUICKACK = 1
[2011/05/10 19:29:07.842408, 5, pid=3540] lib/util_sock.c:304(print_socket_options)
Socket options:
SO_KEEPALIVE = 1
SO_REUSEADDR = 1
SO_BROADCAST = 0
TCP_NODELAY = 1
TCP_KEEPCNT = 9
TCP_KEEPIDLE = 7200
TCP_KEEPINTVL = 75
IPTOS_LOWDELAY = 0
IPTOS_THROUGHPUT = 0
SO_SNDBUF = 16384
SO_RCVBUF = 87380
SO_SNDLOWAT = 1
SO_RCVLOWAT = 1
SO_SNDTIMEO = 0
SO_RCVTIMEO = 0
TCP_QUICKACK = 1
[2011/05/10 19:29:07.842991, 6, pid=3540] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:07.843448, 3, pid=3540] smbd/oplock.c:894(init_oplocks)
init_oplocks: initializing messages.
[2011/05/10 19:29:07.843567, 3, pid=3540] smbd/oplock_linux.c:224(linux_init_kernel_oplocks)
Linux kernel oplocks enabled
[2011/05/10 19:29:07.843587, 5, pid=3540] lib/messages.c:329(messaging_deregister)
Deregistering messaging pointer for type 1 - private_data=(nil)
[2011/05/10 19:29:07.843650, 10, pid=3540] smbd/process.c:740(event_add_idle)
event_add_idle: idle_evt(keepalive) 0x2b67a274f930
[2011/05/10 19:29:07.843670, 10, pid=3540] smbd/process.c:740(event_add_idle)
event_add_idle: idle_evt(deadtime) 0x2b67a2758220
[2011/05/10 19:29:07.843684, 10, pid=3540] smbd/process.c:740(event_add_idle)
event_add_idle: idle_evt(housekeeping) 0x2b67a27450e0
[2011/05/10 19:29:07.843782, 10, pid=3540] lib/util_sock.c:731(read_smb_length_return_keepalive)
got smb length of 133
[2011/05/10 19:29:07.843811, 6, pid=3540] smbd/process.c:1482(process_smb)
got message type 0x0 of len 0x85
[2011/05/10 19:29:07.843831, 3, pid=3540] smbd/process.c:1485(process_smb)
Transaction 0 of length 137 (0 toread)
[2011/05/10 19:29:07.843843, 5, pid=3540] lib/util.c:617(show_msg)
[2011/05/10 19:29:07.843852, 5, pid=3540] lib/util.c:627(show_msg)
size=133
smb_com=0x72
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51283
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=0
smt_wct=0
smb_bcc=98
[2011/05/10 19:29:07.843894, 10, pid=3540] ../lib/util/util.c:278(_dump_data)
[0000] 02 50 43 20 4E 45 54 57 4F 52 4B 20 50 52 4F 47 .PC NETW ORK PROG
[0010] 52 41 4D 20 31 2E 30 00 02 4C 41 4E 4D 41 4E 31 RAM 1.0. .LANMAN1
[0020] 2E 30 00 02 57 69 6E 64 6F 77 73 20 66 6F 72 20 .0..Wind ows for
[0030] 57 6F 72 6B 67 72 6F 75 70 73 20 33 2E 31 61 00 Workgrou ps 3.1a.
[0040] 02 4C 4D 31 2E 32 58 30 30 32 00 02 4C 41 4E 4D .LM1.2X0 02..LANM
[0050] 41 4E 32 2E 31 00 02 4E 54 20 4C 4D 20 30 2E 31 AN2.1..N T LM 0.1
[0060] 32 00 2.
[2011/05/10 19:29:07.844052, 3, pid=3540] smbd/process.c:1294(switch_message)
switch message SMBnegprot (pid 3540) conn 0x0
[2011/05/10 19:29:07.844076, 3, pid=3540] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:07.844103, 5, pid=3540] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:07.844129, 5, pid=3540] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:07.844185, 5, pid=3540] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:07.844363, 3, pid=3540] smbd/negprot.c:586(reply_negprot)
Requested protocol [PC NETWORK PROGRAM 1.0]
[2011/05/10 19:29:07.844384, 3, pid=3540] smbd/negprot.c:586(reply_negprot)
Requested protocol [LANMAN1.0]
[2011/05/10 19:29:07.844410, 3, pid=3540] smbd/negprot.c:586(reply_negprot)
Requested protocol [Windows for Workgroups 3.1a]
[2011/05/10 19:29:07.844423, 3, pid=3540] smbd/negprot.c:586(reply_negprot)
Requested protocol [LM1.2X002]
[2011/05/10 19:29:07.844435, 3, pid=3540] smbd/negprot.c:586(reply_negprot)
Requested protocol [LANMAN2.1]
[2011/05/10 19:29:07.844447, 3, pid=3540] smbd/negprot.c:586(reply_negprot)
Requested protocol [NT LM 0.12]
[2011/05/10 19:29:07.844471, 10, pid=3540] lib/util.c:1969(set_remote_arch)
set_remote_arch: Client arch is 'Win2K'
[2011/05/10 19:29:07.844498, 6, pid=3540] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:07.844527, 5, pid=3540] smbd/connection.c:142(claim_connection)
claiming []
[2011/05/10 19:29:07.844600, 10, pid=3540] lib/dbwrap_tdb.c:100(db_tdb_fetch_locked)
Locking key D40D0000FFFFFFFFFFFF
[2011/05/10 19:29:07.844654, 10, pid=3540] lib/dbwrap_tdb.c:129(db_tdb_fetch_locked)
Allocated locked data 0x0x2b67a27e6f90
[2011/05/10 19:29:07.844729, 10, pid=3540] lib/dbwrap_tdb.c:42(db_tdb_record_destr)
Unlocking key D40D0000FFFFFFFFFFFF
[2011/05/10 19:29:07.844793, 6, pid=3540] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:07.845033, 10, pid=3540] lib/util.c:2598(name_to_fqdn)
name_to_fqdn: lookup for NPSMTP000 -> npsmtp000.child.root.pri.
[2011/05/10 19:29:07.845103, 3, pid=3540] smbd/negprot.c:404(reply_nt1)
using SPNEGO
[2011/05/10 19:29:07.845120, 3, pid=3540] smbd/negprot.c:691(reply_negprot)
Selected protocol NT LM 0.12
[2011/05/10 19:29:07.845131, 5, pid=3540] smbd/negprot.c:698(reply_negprot)
negprot index=5
[2011/05/10 19:29:07.845141, 5, pid=3540] lib/util.c:617(show_msg)
[2011/05/10 19:29:07.845148, 5, pid=3540] lib/util.c:627(show_msg)
size=193
smb_com=0x72
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=136
smb_flg2=51283
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=0
smt_wct=17
smb_vwv[ 0]= 5 (0x5)
smb_vwv[ 1]=12803 (0x3203)
smb_vwv[ 2]= 256 (0x100)
smb_vwv[ 3]= 1024 (0x400)
smb_vwv[ 4]= 65 (0x41)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 256 (0x100)
smb_vwv[ 7]=54272 (0xD400)
smb_vwv[ 8]= 13 (0xD)
smb_vwv[ 9]=64768 (0xFD00)
smb_vwv[10]=33011 (0x80F3)
smb_vwv[11]=32896 (0x8080)
smb_vwv[12]=28387 (0x6EE3)
smb_vwv[13]=27150 (0x6A0E)
smb_vwv[14]=52239 (0xCC0F)
smb_vwv[15]=61441 (0xF001)
smb_vwv[16]= 0 (0x0)
smb_bcc=124
[2011/05/10 19:29:07.845237, 10, pid=3540] ../lib/util/util.c:278(_dump_data)
[0000] 6E 70 73 6D 74 70 30 30 30 00 00 00 00 00 00 00 npsmtp00 0.......
[0010] 60 6A 06 06 2B 06 01 05 05 02 A0 60 30 5E A0 24 `j..+... ...`0^.$
[0020] 30 22 06 09 2A 86 48 86 F7 12 01 02 02 06 09 2A 0"..*.H. .......*
[0030] 86 48 82 F7 12 01 02 02 06 0A 2B 06 01 04 01 82 .H...... ..+.....
[0040] 37 02 02 0A A3 36 30 34 A0 32 1B 30 63 69 66 73 7....604 .2.0cifs
[0050] 2F 6E 70 73 6D 74 70 30 30 30 2E 6B 66 62 64 6F /npsmtp0 00.kfbdo
[0060] 6D 31 2E 6B 79 66 62 2E 70 72 69 40 4B 46 42 44 m1.kyfb. pri@KFBD
[0070] 4F 4D 31 2E 4B 59 46 42 2E 50 52 49 OM1.KYFB .PRI
[2011/05/10 19:29:10.098010, 10, pid=3540] lib/util_sock.c:731(read_smb_length_return_keepalive)
got smb length of 236
[2011/05/10 19:29:10.098115, 6, pid=3540] smbd/process.c:1482(process_smb)
got message type 0x0 of len 0xec
[2011/05/10 19:29:10.098129, 3, pid=3540] smbd/process.c:1485(process_smb)
Transaction 1 of length 240 (0 toread)
[2011/05/10 19:29:10.098141, 5, pid=3540] lib/util.c:617(show_msg)
[2011/05/10 19:29:10.098149, 5, pid=3540] lib/util.c:627(show_msg)
size=236
smb_com=0x73
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=0
smb_pid=65279
smb_uid=0
smb_mid=64
smt_wct=12
smb_vwv[ 0]= 255 (0xFF)
smb_vwv[ 1]= 236 (0xEC)
smb_vwv[ 2]=16644 (0x4104)
smb_vwv[ 3]= 50 (0x32)
smb_vwv[ 4]= 0 (0x0)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 0 (0x0)
smb_vwv[ 7]= 74 (0x4A)
smb_vwv[ 8]= 0 (0x0)
smb_vwv[ 9]= 0 (0x0)
smb_vwv[10]= 212 (0xD4)
smb_vwv[11]=40960 (0xA000)
smb_bcc=177
[2011/05/10 19:29:10.098235, 10, pid=3540] ../lib/util/util.c:278(_dump_data)
[0000] 60 48 06 06 2B 06 01 05 05 02 A0 3E 30 3C A0 0E `H..+... ...>0<..
[0010] 30 0C 06 0A 2B 06 01 04 01 82 37 02 02 0A A2 2A 0...+... ..7....*
[0020] 04 28 4E 54 4C 4D 53 53 50 00 01 00 00 00 07 82 .(NTLMSS P.......
[0030] 08 A2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........ ........
[0040] 00 00 05 01 28 0A 00 00 00 0F 00 57 00 69 00 6E ....(... ...W.i.n
[0050] 00 64 00 6F 00 77 00 73 00 20 00 32 00 30 00 30 .d.o.w.s . .2.0.0
[0060] 00 32 00 20 00 53 00 65 00 72 00 76 00 69 00 63 .2. .S.e .r.v.i.c
[0070] 00 65 00 20 00 50 00 61 00 63 00 6B 00 20 00 33 .e. .P.a .c.k. .3
[0080] 00 20 00 32 00 36 00 30 00 30 00 00 00 57 00 69 . .2.6.0 .0...W.i
[0090] 00 6E 00 64 00 6F 00 77 00 73 00 20 00 32 00 30 .n.d.o.w .s. .2.0
[00A0] 00 30 00 32 00 20 00 35 00 2E 00 31 00 00 00 00 .0.2. .5 ...1....
[00B0] 00 .
[2011/05/10 19:29:10.098428, 3, pid=3540] smbd/process.c:1294(switch_message)
switch message SMBsesssetupX (pid 3540) conn 0x0
[2011/05/10 19:29:10.098460, 3, pid=3540] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:10.098477, 5, pid=3540] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:10.098490, 5, pid=3540] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:10.098521, 5, pid=3540] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:10.098586, 3, pid=3540] smbd/sesssetup.c:1435(reply_sesssetup_and_X)
wct=12 flg2=0xc807
[2011/05/10 19:29:10.098613, 2, pid=3540] smbd/sesssetup.c:1390(setup_new_vc_session)
setup_new_vc_session: New VC == 0, if NT4.x compatible we would close all old resources.
[2011/05/10 19:29:10.098674, 3, pid=3540] smbd/sesssetup.c:1189(reply_sesssetup_and_X_spnego)
Doing spnego session setup
[2011/05/10 19:29:10.098742, 3, pid=3540] smbd/sesssetup.c:1231(reply_sesssetup_and_X_spnego)
NativeOS=[Windows 2002 Service Pack 3 2600] NativeLanMan=[Windows 2002 5.1] PrimaryDomain=[]
[2011/05/10 19:29:10.098760, 10, pid=3540] lib/util.c:1969(set_remote_arch)
set_remote_arch: Client arch is 'WinXP'
[2011/05/10 19:29:10.098787, 10, pid=3540] smbd/password.c:184(register_initial_vuid)
register_initial_vuid: allocated vuid = 100
[2011/05/10 19:29:10.098813, 10, pid=3540] smbd/sesssetup.c:1134(check_spnego_blob_complete)
check_spnego_blob_complete: needed_len = 74, pblob->length = 74
[2011/05/10 19:29:10.098852, 5, pid=3540] smbd/sesssetup.c:753(parse_spnego_mechanisms)
parse_spnego_mechanisms: Got OID 1.3.6.1.4.1.311.2.2.10
[2011/05/10 19:29:10.098867, 3, pid=3540] smbd/sesssetup.c:805(reply_spnego_negotiate)
reply_spnego_negotiate: Got secblob of size 40
[2011/05/10 19:29:10.098950, 5, pid=3540] auth/auth.c:510(make_auth_context_subsystem)
Making default auth method list for security=ADS
[2011/05/10 19:29:10.098979, 5, pid=3540] auth/auth.c:46(smb_register_auth)
Attempting to register auth backend sam
[2011/05/10 19:29:10.098993, 5, pid=3540] auth/auth.c:58(smb_register_auth)
Successfully added auth method 'sam'
[2011/05/10 19:29:10.099004, 5, pid=3540] auth/auth.c:46(smb_register_auth)
Attempting to register auth backend sam_ignoredomain
[2011/05/10 19:29:10.099015, 5, pid=3540] auth/auth.c:58(smb_register_auth)
Successfully added auth method 'sam_ignoredomain'
[2011/05/10 19:29:10.099030, 5, pid=3540] auth/auth.c:46(smb_register_auth)
Attempting to register auth backend unix
[2011/05/10 19:29:10.099043, 5, pid=3540] auth/auth.c:58(smb_register_auth)
Successfully added auth method 'unix'
[2011/05/10 19:29:10.099059, 5, pid=3540] auth/auth.c:46(smb_register_auth)
Attempting to register auth backend winbind
[2011/05/10 19:29:10.099071, 5, pid=3540] auth/auth.c:58(smb_register_auth)
Successfully added auth method 'winbind'
[2011/05/10 19:29:10.099082, 5, pid=3540] auth/auth.c:46(smb_register_auth)
Attempting to register auth backend wbc
[2011/05/10 19:29:10.099094, 5, pid=3540] auth/auth.c:58(smb_register_auth)
Successfully added auth method 'wbc'
[2011/05/10 19:29:10.099105, 5, pid=3540] auth/auth.c:46(smb_register_auth)
Attempting to register auth backend smbserver
[2011/05/10 19:29:10.099116, 5, pid=3540] auth/auth.c:58(smb_register_auth)
Successfully added auth method 'smbserver'
[2011/05/10 19:29:10.099157, 5, pid=3540] auth/auth.c:46(smb_register_auth)
Attempting to register auth backend trustdomain
[2011/05/10 19:29:10.099170, 5, pid=3540] auth/auth.c:58(smb_register_auth)
Successfully added auth method 'trustdomain'
[2011/05/10 19:29:10.099181, 5, pid=3540] auth/auth.c:46(smb_register_auth)
Attempting to register auth backend ntdomain
[2011/05/10 19:29:10.099192, 5, pid=3540] auth/auth.c:58(smb_register_auth)
Successfully added auth method 'ntdomain'
[2011/05/10 19:29:10.099208, 5, pid=3540] auth/auth.c:46(smb_register_auth)
Attempting to register auth backend guest
[2011/05/10 19:29:10.099221, 5, pid=3540] auth/auth.c:58(smb_register_auth)
Successfully added auth method 'guest'
[2011/05/10 19:29:10.099233, 5, pid=3540] auth/auth.c:46(smb_register_auth)
Attempting to register auth backend netlogond
[2011/05/10 19:29:10.099251, 5, pid=3540] auth/auth.c:58(smb_register_auth)
Successfully added auth method 'netlogond'
[2011/05/10 19:29:10.099262, 5, pid=3540] auth/auth.c:383(load_auth_module)
load_auth_module: Attempting to find an auth method to match guest
[2011/05/10 19:29:10.099280, 5, pid=3540] auth/auth.c:408(load_auth_module)
load_auth_module: auth method guest has a valid init
[2011/05/10 19:29:10.099293, 5, pid=3540] auth/auth.c:383(load_auth_module)
load_auth_module: Attempting to find an auth method to match sam
[2011/05/10 19:29:10.099305, 5, pid=3540] auth/auth.c:408(load_auth_module)
load_auth_module: auth method sam has a valid init
[2011/05/10 19:29:10.099316, 5, pid=3540] auth/auth.c:383(load_auth_module)
load_auth_module: Attempting to find an auth method to match winbind:ntdomain
[2011/05/10 19:29:10.099329, 5, pid=3540] auth/auth.c:383(load_auth_module)
load_auth_module: Attempting to find an auth method to match ntdomain
[2011/05/10 19:29:10.099340, 5, pid=3540] auth/auth.c:408(load_auth_module)
load_auth_module: auth method ntdomain has a valid init
[2011/05/10 19:29:10.099396, 5, pid=3540] auth/auth.c:408(load_auth_module)
load_auth_module: auth method winbind has a valid init
[2011/05/10 19:29:10.099480, 3, pid=3540] libsmb/ntlmssp.c:65(debug_ntlmssp_flags)
Got NTLMSSP neg_flags=0xa2088207
NTLMSSP_NEGOTIATE_UNICODE
NTLMSSP_NEGOTIATE_OEM
NTLMSSP_REQUEST_TARGET
NTLMSSP_NEGOTIATE_NTLM
NTLMSSP_NEGOTIATE_ALWAYS_SIGN
NTLMSSP_NEGOTIATE_NTLM2
NTLMSSP_NEGOTIATE_VERSION
NTLMSSP_NEGOTIATE_128
NTLMSSP_NEGOTIATE_56
[2011/05/10 19:29:10.099592, 1, pid=3540] ../librpc/ndr/ndr.c:214(ndr_print_debug)
&negotiate: struct NEGOTIATE_MESSAGE
Signature : 'NTLMSSP'
MessageType : NtLmNegotiate (1)
NegotiateFlags : 0xa2088207 (2718466567)
1: NTLMSSP_NEGOTIATE_UNICODE
1: NTLMSSP_NEGOTIATE_OEM
1: NTLMSSP_REQUEST_TARGET
0: NTLMSSP_NEGOTIATE_SIGN
0: NTLMSSP_NEGOTIATE_SEAL
0: NTLMSSP_NEGOTIATE_DATAGRAM
0: NTLMSSP_NEGOTIATE_LM_KEY
0: NTLMSSP_NEGOTIATE_NETWARE
1: NTLMSSP_NEGOTIATE_NTLM
0: NTLMSSP_NEGOTIATE_NT_ONLY
0: NTLMSSP_ANONYMOUS
0: NTLMSSP_NEGOTIATE_OEM_DOMAIN_SUPPLIED
0: NTLMSSP_NEGOTIATE_OEM_WORKSTATION_SUPPLIED
0: NTLMSSP_NEGOTIATE_THIS_IS_LOCAL_CALL
1: NTLMSSP_NEGOTIATE_ALWAYS_SIGN
0: NTLMSSP_TARGET_TYPE_DOMAIN
0: NTLMSSP_TARGET_TYPE_SERVER
0: NTLMSSP_TARGET_TYPE_SHARE
1: NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
0: NTLMSSP_NEGOTIATE_IDENTIFY
0: NTLMSSP_REQUEST_NON_NT_SESSION_KEY
0: NTLMSSP_NEGOTIATE_TARGET_INFO
1: NTLMSSP_NEGOTIATE_VERSION
1: NTLMSSP_NEGOTIATE_128
0: NTLMSSP_NEGOTIATE_KEY_EXCH
1: NTLMSSP_NEGOTIATE_56
DomainNameLen : 0x0000 (0)
DomainNameMaxLen : 0x0000 (0)
DomainName : NULL
WorkstationLen : 0x0000 (0)
WorkstationMaxLen : 0x0000 (0)
Workstation : NULL
Version: struct VERSION
ProductMajorVersion : NTLMSSP_WINDOWS_MAJOR_VERSION_5 (5)
ProductMinorVersion : NTLMSSP_WINDOWS_MINOR_VERSION_1 (1)
ProductBuild : 0x0a28 (2600)
Reserved: ARRAY(3)
[0] : 0x00 (0)
[1] : 0x00 (0)
[2] : 0x00 (0)
NTLMRevisionCurrent : NTLMSSP_REVISION_W2K3 (15)
[2011/05/10 19:29:10.099838, 5, pid=3540] auth/auth.c:97(get_ntlm_challenge)
auth_get_challenge: module guest did not want to specify a challenge
[2011/05/10 19:29:10.099852, 5, pid=3540] auth/auth.c:97(get_ntlm_challenge)
auth_get_challenge: module sam did not want to specify a challenge
[2011/05/10 19:29:10.099864, 5, pid=3540] auth/auth.c:97(get_ntlm_challenge)
auth_get_challenge: module winbind did not want to specify a challenge
[2011/05/10 19:29:10.099889, 5, pid=3540] auth/auth.c:132(get_ntlm_challenge)
auth_context challenge created by random
[2011/05/10 19:29:10.099901, 5, pid=3540] auth/auth.c:133(get_ntlm_challenge)
challenge is:
[2011/05/10 19:29:10.099911, 5, pid=3540] ../lib/util/util.c:278(_dump_data)
[0000] E3 41 F9 55 25 0B 8C 72 .A.U%..r
[2011/05/10 19:29:10.100323, 1, pid=3540] ../librpc/ndr/ndr.c:214(ndr_print_debug)
&challenge: struct CHALLENGE_MESSAGE
Signature : 'NTLMSSP'
MessageType : NtLmChallenge (0x2)
TargetNameLen : 0x000c (12)
TargetNameMaxLen : 0x000c (12)
TargetName : *
TargetName : 'TESTER'
NegotiateFlags : 0xa2898205 (2726920709)
1: NTLMSSP_NEGOTIATE_UNICODE
0: NTLMSSP_NEGOTIATE_OEM
1: NTLMSSP_REQUEST_TARGET
0: NTLMSSP_NEGOTIATE_SIGN
0: NTLMSSP_NEGOTIATE_SEAL
0: NTLMSSP_NEGOTIATE_DATAGRAM
0: NTLMSSP_NEGOTIATE_LM_KEY
0: NTLMSSP_NEGOTIATE_NETWARE
1: NTLMSSP_NEGOTIATE_NTLM
0: NTLMSSP_NEGOTIATE_NT_ONLY
0: NTLMSSP_ANONYMOUS
0: NTLMSSP_NEGOTIATE_OEM_DOMAIN_SUPPLIED
0: NTLMSSP_NEGOTIATE_OEM_WORKSTATION_SUPPLIED
0: NTLMSSP_NEGOTIATE_THIS_IS_LOCAL_CALL
1: NTLMSSP_NEGOTIATE_ALWAYS_SIGN
1: NTLMSSP_TARGET_TYPE_DOMAIN
0: NTLMSSP_TARGET_TYPE_SERVER
0: NTLMSSP_TARGET_TYPE_SHARE
1: NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
0: NTLMSSP_NEGOTIATE_IDENTIFY
0: NTLMSSP_REQUEST_NON_NT_SESSION_KEY
1: NTLMSSP_NEGOTIATE_TARGET_INFO
1: NTLMSSP_NEGOTIATE_VERSION
1: NTLMSSP_NEGOTIATE_128
0: NTLMSSP_NEGOTIATE_KEY_EXCH
1: NTLMSSP_NEGOTIATE_56
ServerChallenge : e341f955250b8c72
Reserved : 0000000000000000
TargetInfoLen : 0x0086 (134)
TargetNameInfoMaxLen : 0x0086 (134)
TargetInfo : *
TargetInfo: struct AV_PAIR_LIST
count : 0x00000005 (5)
pair: ARRAY(5)
pair: struct AV_PAIR
AvId : MsvAvNbDomainName (0x2)
AvLen : 0x000c (12)
Value : union ntlmssp_AvValue(case 0x2)
AvNbDomainName : 'TESTER'
pair: struct AV_PAIR
AvId : MsvAvNbComputerName (0x1)
AvLen : 0x0012 (18)
Value : union ntlmssp_AvValue(case 0x1)
AvNbComputerName : 'NPSMTP000'
pair: struct AV_PAIR
AvId : MsvAvDnsDomainName (0x4)
AvLen : 0x0020 (32)
Value : union ntlmssp_AvValue(case 0x4)
AvDnsDomainName : 'child.root.pri'
pair: struct AV_PAIR
AvId : MsvAvDnsComputerName (0x3)
AvLen : 0x0034 (52)
Value : union ntlmssp_AvValue(case 0x3)
AvDnsComputerName : 'npsmtp000.child.root.pri'
pair: struct AV_PAIR
AvId : MsvAvEOL (0x0)
AvLen : 0x0000 (0)
Value : union ntlmssp_AvValue(case 0x0)
Version: struct VERSION
ProductMajorVersion : UNKNOWN_ENUM_VALUE (0x54)
ProductMinorVersion : NTLMSSP_WINDOWS_MINOR_VERSION_0 (0x0)
ProductBuild : 0x0045 (69)
Reserved : 530054
NTLMRevisionCurrent : UNKNOWN_ENUM_VALUE (0x0)
[2011/05/10 19:29:10.100797, 5, pid=3540] lib/util.c:617(show_msg)
[2011/05/10 19:29:10.100808, 5, pid=3540] lib/util.c:627(show_msg)
size=342
smb_com=0x73
smb_rcls=22
smb_reh=0
smb_err=49152
smb_flg=136
smb_flg2=51203
smb_tid=0
smb_pid=65279
smb_uid=100
smb_mid=64
smt_wct=4
smb_vwv[ 0]= 255 (0xFF)
smb_vwv[ 1]= 0 (0x0)
smb_vwv[ 2]= 0 (0x0)
smb_vwv[ 3]= 225 (0xE1)
smb_bcc=299
[2011/05/10 19:29:10.100861, 10, pid=3540] ../lib/util/util.c:278(_dump_data)
[0000] A1 81 DE 30 81 DB A0 03 0A 01 01 A1 0C 06 0A 2B ...0.... .......+
[0010] 06 01 04 01 82 37 02 02 0A A2 81 C5 04 81 C2 4E .....7.. .......N
[0020] 54 4C 4D 53 53 50 00 02 00 00 00 0C 00 0C 00 30 TLMSSP.. .......0
[0030] 00 00 00 05 82 89 A2 E3 41 F9 55 25 0B 8C 72 00 ........ A.U%..r.
[0040] 00 00 00 00 00 00 00 86 00 86 00 3C 00 00 00 54 ........ ...<...T
[0050] 00 45 00 53 00 54 00 45 00 52 00 02 00 0C 00 54 .E.S.T.E .R.....T
[0060] 00 45 00 53 00 54 00 45 00 52 00 01 00 12 00 4E .E.S.T.E .R.....N
[0070] 00 50 00 53 00 4D 00 54 00 50 00 30 00 30 00 30 .P.S.M.T .P.0.0.0
[0080] 00 04 00 20 00 6B 00 66 00 62 00 64 00 6F 00 6D ... .k.f .b.d.o.m
[0090] 00 31 00 2E 00 6B 00 79 00 66 00 62 00 2E 00 70 .1...k.y .f.b...p
[00A0] 00 72 00 69 00 03 00 34 00 6E 00 70 00 73 00 6D .r.i...4 .n.p.s.m
[00B0] 00 74 00 70 00 30 00 30 00 30 00 2E 00 6B 00 66 .t.p.0.0 .0...k.f
[00C0] 00 62 00 64 00 6F 00 6D 00 31 00 2E 00 6B 00 79 .b.d.o.m .1...k.y
[00D0] 00 66 00 62 00 2E 00 70 00 72 00 69 00 00 00 00 .f.b...p .r.i....
[00E0] 00 55 00 6E 00 69 00 78 00 00 00 53 00 61 00 6D .U.n.i.x ...S.a.m
[00F0] 00 62 00 61 00 20 00 33 00 2E 00 35 00 2E 00 34 .b.a. .3 ...5...4
[0100] 00 2D 00 30 00 2E 00 37 00 30 00 2E 00 65 00 6C .-.0...7 .0...e.l
[0110] 00 35 00 5F 00 36 00 2E 00 31 00 00 00 54 00 45 .5._.6.. .1...T.E
[0120] 00 53 00 54 00 45 00 52 00 00 00 .S.T.E.R ...
[2011/05/10 19:29:10.101905, 10, pid=3540] lib/util_sock.c:731(read_smb_length_return_keepalive)
got smb length of 340
[2011/05/10 19:29:10.101929, 6, pid=3540] smbd/process.c:1482(process_smb)
got message type 0x0 of len 0x154
[2011/05/10 19:29:10.101942, 3, pid=3540] smbd/process.c:1485(process_smb)
Transaction 2 of length 344 (0 toread)
[2011/05/10 19:29:10.101954, 5, pid=3540] lib/util.c:617(show_msg)
[2011/05/10 19:29:10.101962, 5, pid=3540] lib/util.c:627(show_msg)
size=340
smb_com=0x73
smb_rcls=0
smb_reh=0
smb_err=0
smb_flg=24
smb_flg2=51207
smb_tid=0
smb_pid=65279
smb_uid=100
smb_mid=128
smt_wct=12
smb_vwv[ 0]= 255 (0xFF)
smb_vwv[ 1]= 340 (0x154)
smb_vwv[ 2]=16644 (0x4104)
smb_vwv[ 3]= 50 (0x32)
smb_vwv[ 4]= 0 (0x0)
smb_vwv[ 5]= 0 (0x0)
smb_vwv[ 6]= 0 (0x0)
smb_vwv[ 7]= 178 (0xB2)
smb_vwv[ 8]= 0 (0x0)
smb_vwv[ 9]= 0 (0x0)
smb_vwv[10]= 212 (0xD4)
smb_vwv[11]=40960 (0xA000)
smb_bcc=281
[2011/05/10 19:29:10.102042, 10, pid=3540] ../lib/util/util.c:278(_dump_data)
[0000] A1 81 AF 30 81 AC A2 81 A9 04 81 A6 4E 54 4C 4D ...0.... ....NTLM
[0010] 53 53 50 00 03 00 00 00 18 00 18 00 76 00 00 00 SSP..... ....v...
[0020] 18 00 18 00 8E 00 00 00 12 00 12 00 48 00 00 00 ........ ....H...
[0030] 0E 00 0E 00 5A 00 00 00 0E 00 0E 00 68 00 00 00 ....Z... ....h...
[0040] 00 00 00 00 A6 00 00 00 05 82 88 A2 05 01 28 0A ........ ......(.
[0050] 00 00 00 0F 4E 00 50 00 53 00 4D 00 54 00 50 00 ....N.P. S.M.T.P.
[0060] 30 00 30 00 30 00 61 00 6A 00 61 00 32 00 34 00 0.0.0.a. j.a.2.4.
[0070] 35 00 30 00 53 00 58 00 43 00 48 00 31 00 30 00 5.0.S.X. C.H.1.0.
[0080] 31 00 F4 CE 0C FB E5 38 D2 C3 00 00 00 00 00 00 1......8 ........
[0090] 00 00 00 00 00 00 00 00 00 00 63 AA 09 C7 14 22 ........ ..c...."
[00A0] C0 46 30 7B A0 90 61 8B C9 23 34 C3 4B A1 E0 E7 .F0{..a. .#4.K...
[00B0] 26 3D 00 57 00 69 00 6E 00 64 00 6F 00 77 00 73 &=.W.i.n .d.o.w.s
[00C0] 00 20 00 32 00 30 00 30 00 32 00 20 00 53 00 65 . .2.0.0 .2. .S.e
[00D0] 00 72 00 76 00 69 00 63 00 65 00 20 00 50 00 61 .r.v.i.c .e. .P.a
[00E0] 00 63 00 6B 00 20 00 33 00 20 00 32 00 36 00 30 .c.k. .3 . .2.6.0
[00F0] 00 30 00 00 00 57 00 69 00 6E 00 64 00 6F 00 77 .0...W.i .n.d.o.w
[0100] 00 73 00 20 00 32 00 30 00 30 00 32 00 20 00 35 .s. .2.0 .0.2. .5
[0110] 00 2E 00 31 00 00 00 00 00 ...1.... .
[2011/05/10 19:29:10.102235, 3, pid=3540] smbd/process.c:1294(switch_message)
switch message SMBsesssetupX (pid 3540) conn 0x0
[2011/05/10 19:29:10.102248, 3, pid=3540] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:10.102260, 5, pid=3540] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:10.102270, 5, pid=3540] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:10.102302, 5, pid=3540] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:10.102316, 3, pid=3540] smbd/sesssetup.c:1435(reply_sesssetup_and_X)
wct=12 flg2=0xc807
[2011/05/10 19:29:10.102328, 2, pid=3540] smbd/sesssetup.c:1390(setup_new_vc_session)
setup_new_vc_session: New VC == 0, if NT4.x compatible we would close all old resources.
[2011/05/10 19:29:10.102339, 3, pid=3540] smbd/sesssetup.c:1189(reply_sesssetup_and_X_spnego)
Doing spnego session setup
[2011/05/10 19:29:10.102353, 3, pid=3540] smbd/sesssetup.c:1231(reply_sesssetup_and_X_spnego)
NativeOS=[Windows 2002 Service Pack 3 2600] NativeLanMan=[Windows 2002 5.1] PrimaryDomain=[]
[2011/05/10 19:29:10.102366, 10, pid=3540] smbd/sesssetup.c:1134(check_spnego_blob_complete)
check_spnego_blob_complete: needed_len = 178, pblob->length = 178
[2011/05/10 19:29:10.102403, 1, pid=3540] ../librpc/ndr/ndr.c:214(ndr_print_debug)
&authenticate: struct AUTHENTICATE_MESSAGE
Signature : 'NTLMSSP'
MessageType : NtLmAuthenticate (3)
LmChallengeResponseLen : 0x0018 (24)
LmChallengeResponseMaxLen: 0x0018 (24)
LmChallengeResponse : *
LmChallengeResponse : union ntlmssp_LM_RESPONSE(case 24)
v1: struct LM_RESPONSE
Response : f4ce0cfbe538d2c300000000000000000000000000000000
NtChallengeResponseLen : 0x0018 (24)
NtChallengeResponseMaxLen: 0x0018 (24)
NtChallengeResponse : *
NtChallengeResponse : union ntlmssp_NTLM_RESPONSE(case 24)
v1: struct NTLM_RESPONSE
Response : 63aa09c71422c046307ba090618bc92334c34ba1e0e7263d
DomainNameLen : 0x0012 (18)
DomainNameMaxLen : 0x0012 (18)
DomainName : *
DomainName : 'NPSMTP000'
UserNameLen : 0x000e (14)
UserNameMaxLen : 0x000e (14)
UserName : *
UserName : 'useraccount'
WorkstationLen : 0x000e (14)
WorkstationMaxLen : 0x000e (14)
Workstation : *
Workstation : 'SXCH101'
EncryptedRandomSessionKeyLen: 0x0000 (0)
EncryptedRandomSessionKeyMaxLen: 0x0000 (0)
EncryptedRandomSessionKey: *
EncryptedRandomSessionKey: DATA_BLOB length=0
NegotiateFlags : 0xa2888205 (2726855173)
1: NTLMSSP_NEGOTIATE_UNICODE
0: NTLMSSP_NEGOTIATE_OEM
1: NTLMSSP_REQUEST_TARGET
0: NTLMSSP_NEGOTIATE_SIGN
0: NTLMSSP_NEGOTIATE_SEAL
0: NTLMSSP_NEGOTIATE_DATAGRAM
0: NTLMSSP_NEGOTIATE_LM_KEY
0: NTLMSSP_NEGOTIATE_NETWARE
1: NTLMSSP_NEGOTIATE_NTLM
0: NTLMSSP_NEGOTIATE_NT_ONLY
0: NTLMSSP_ANONYMOUS
0: NTLMSSP_NEGOTIATE_OEM_DOMAIN_SUPPLIED
0: NTLMSSP_NEGOTIATE_OEM_WORKSTATION_SUPPLIED
0: NTLMSSP_NEGOTIATE_THIS_IS_LOCAL_CALL
1: NTLMSSP_NEGOTIATE_ALWAYS_SIGN
0: NTLMSSP_TARGET_TYPE_DOMAIN
0: NTLMSSP_TARGET_TYPE_SERVER
0: NTLMSSP_TARGET_TYPE_SHARE
1: NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
0: NTLMSSP_NEGOTIATE_IDENTIFY
0: NTLMSSP_REQUEST_NON_NT_SESSION_KEY
1: NTLMSSP_NEGOTIATE_TARGET_INFO
1: NTLMSSP_NEGOTIATE_VERSION
1: NTLMSSP_NEGOTIATE_128
0: NTLMSSP_NEGOTIATE_KEY_EXCH
1: NTLMSSP_NEGOTIATE_56
Version: struct VERSION
ProductMajorVersion : NTLMSSP_WINDOWS_MAJOR_VERSION_5 (5)
ProductMinorVersion : NTLMSSP_WINDOWS_MINOR_VERSION_1 (1)
ProductBuild : 0x0a28 (2600)
Reserved: ARRAY(3)
[0] : 0x00 (0)
[1] : 0x00 (0)
[2] : 0x00 (0)
NTLMRevisionCurrent : NTLMSSP_REVISION_W2K3 (15)
[2011/05/10 19:29:10.102756, 3, pid=3540] libsmb/ntlmssp.c:747(ntlmssp_server_auth)
Got user=[useraccount] domain=[NPSMTP000] workstation=[SXCH101] len1=24 len2=24
[2011/05/10 19:29:10.102782, 5, pid=3540] auth/auth_ntlmssp.c:70(auth_ntlmssp_set_challenge)
auth_context challenge set by NTLMSSP callback (NTLM2)
[2011/05/10 19:29:10.102795, 5, pid=3540] auth/auth_ntlmssp.c:71(auth_ntlmssp_set_challenge)
challenge is:
[2011/05/10 19:29:10.102806, 5, pid=3540] ../lib/util/util.c:278(_dump_data)
[0000] BE AF 01 61 DD 37 28 57 ...a.7(W
[2011/05/10 19:29:10.102868, 6, pid=3540] param/loadparm.c:7144(lp_file_list_changed)
lp_file_list_changed()
file /etc/samba/smb.conf -> /etc/samba/smb.conf last mod_time: Tue May 10 18:44:10 2011
[2011/05/10 19:29:10.102910, 5, pid=3540] auth/auth_util.c:211(make_user_info_map)
Mapping user [NPSMTP000]\[useraccount] from workstation [SXCH101]
[2011/05/10 19:29:10.102938, 5, pid=3540] auth/auth_util.c:232(make_user_info_map)
Mapped domain from [NPSMTP000] to [NPSMTP000] for user [useraccount] from workstation [SXCH101]
[2011/05/10 19:29:10.102955, 5, pid=3540] auth/auth_util.c:122(make_user_info)
attempting to make a user_info for useraccount (useraccount)
[2011/05/10 19:29:10.102968, 5, pid=3540] auth/auth_util.c:132(make_user_info)
making strings for useraccount's user_info struct
[2011/05/10 19:29:10.102979, 5, pid=3540] auth/auth_util.c:164(make_user_info)
making blobs for useraccount's user_info struct
[2011/05/10 19:29:10.102990, 10, pid=3540] auth/auth_util.c:182(make_user_info)
made an encrypted user_info for useraccount (useraccount)
[2011/05/10 19:29:10.103006, 3, pid=3540] auth/auth.c:216(check_ntlm_password)
check_ntlm_password: Checking password for unmapped user [NPSMTP000]\[useraccount]@[SXCH101] with the new password interface
[2011/05/10 19:29:10.103022, 3, pid=3540] auth/auth.c:219(check_ntlm_password)
check_ntlm_password: mapped user is: [NPSMTP000]\[useraccount]@[SXCH101]
[2011/05/10 19:29:10.103033, 10, pid=3540] auth/auth.c:228(check_ntlm_password)
check_ntlm_password: auth_context challenge created by NTLMSSP callback (NTLM2)
[2011/05/10 19:29:10.103044, 10, pid=3540] auth/auth.c:230(check_ntlm_password)
challenge is:
[2011/05/10 19:29:10.103054, 5, pid=3540] ../lib/util/util.c:278(_dump_data)
[0000] BE AF 01 61 DD 37 28 57 ...a.7(W
[2011/05/10 19:29:10.103074, 10, pid=3540] auth/auth.c:256(check_ntlm_password)
check_ntlm_password: guest had nothing to say
[2011/05/10 19:29:10.103088, 8, pid=3540] lib/util.c:1869(is_myname)
is_myname("NPSMTP000") returns 1
[2011/05/10 19:29:10.103115, 3, pid=3540] smbd/sec_ctx.c:210(push_sec_ctx)
push_sec_ctx(0, 0) : sec_ctx_stack_ndx = 1
[2011/05/10 19:29:10.103138, 3, pid=3540] smbd/uid.c:429(push_conn_ctx)
push_conn_ctx(0) : conn_ctx_stack_ndx = 0
[2011/05/10 19:29:10.103151, 3, pid=3540] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 1
[2011/05/10 19:29:10.103162, 5, pid=3540] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:10.103172, 5, pid=3540] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:10.103247, 5, pid=3540] passdb/pdb_tdb.c:557(tdbsam_getsampwnam)
pdb_getsampwnam (TDB): error fetching database.
Key: USER_useraccount
[2011/05/10 19:29:10.103273, 3, pid=3540] smbd/sec_ctx.c:418(pop_sec_ctx)
pop_sec_ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:10.103286, 3, pid=3540] auth/auth_sam.c:399(check_sam_security)
check_sam_security: Couldn't find user 'useraccount' in passdb.
[2011/05/10 19:29:10.103305, 5, pid=3540] auth/auth.c:268(check_ntlm_password)
check_ntlm_password: sam authentication for user [useraccount] FAILED with error NT_STATUS_NO_SUCH_USER
[2011/05/10 19:29:10.103331, 3, pid=3540] auth/auth_winbind.c:54(check_winbind_security)
check_winbind_security: Not using winbind, requested domain [NPSMTP000] was for this SAM.
[2011/05/10 19:29:10.103344, 10, pid=3540] auth/auth.c:256(check_ntlm_password)
check_ntlm_password: winbind had nothing to say
[2011/05/10 19:29:10.103355, 2, pid=3540] auth/auth.c:314(check_ntlm_password)
check_ntlm_password: Authentication for user [useraccount] -> [useraccount] FAILED with error NT_STATUS_NO_SUCH_USER
[2011/05/10 19:29:10.103368, 5, pid=3540] auth/auth_util.c:2119(free_user_info)
attempting to free (and zero) a user_info structure
[2011/05/10 19:29:10.103380, 10, pid=3540] auth/auth_util.c:2123(free_user_info)
structure was created for useraccount
[2011/05/10 19:29:10.103425, 3, pid=3540] smbd/error.c:80(error_packet_set)
error packet at smbd/sesssetup.c(111) cmd=115 (SMBsesssetupX) NT_STATUS_LOGON_FAILURE
[2011/05/10 19:29:10.103462, 5, pid=3540] lib/util.c:617(show_msg)
[2011/05/10 19:29:10.103471, 5, pid=3540] lib/util.c:627(show_msg)
size=35
smb_com=0x73
smb_rcls=109
smb_reh=0
smb_err=49152
smb_flg=136
smb_flg2=51203
smb_tid=0
smb_pid=65279
smb_uid=100
smb_mid=128
smt_wct=0
smb_bcc=0
[2011/05/10 19:29:10.113318, 5, pid=3540] lib/util_sock.c:462(read_fd_with_timeout)
read_fd_with_timeout: blocking read. EOF from client.
[2011/05/10 19:29:10.113365, 10, pid=3540] smbd/process.c:286(receive_smb_raw_talloc)
receive_smb_raw: NT_STATUS_END_OF_FILE
[2011/05/10 19:29:10.113380, 3, pid=3540] smbd/sec_ctx.c:310(set_sec_ctx)
setting sec ctx (0, 0) - sec_ctx_stack_ndx = 0
[2011/05/10 19:29:10.113393, 5, pid=3540] auth/token_util.c:525(debug_nt_user_token)
NT user token: (NULL)
[2011/05/10 19:29:10.113404, 5, pid=3540] auth/token_util.c:551(debug_unix_user_token)
UNIX token of user 0
Primary group is 0 and contains 0 supplementary groups
[2011/05/10 19:29:10.113426, 5, pid=3540] smbd/uid.c:369(change_to_root_user)
change_to_root_user: now uid=(0,0) gid=(0,0)
[2011/05/10 19:29:10.113475, 3, pid=3540] smbd/connection.c:31(yield_connection)
Yielding connection to
[2011/05/10 19:29:10.113525, 10, pid=3540] lib/dbwrap_tdb.c:100(db_tdb_fetch_locked)
Locking key D40D0000FFFFFFFFFFFF
[2011/05/10 19:29:10.113589, 10, pid=3540] lib/dbwrap_tdb.c:129(db_tdb_fetch_locked)
Allocated locked data 0x0x2b67a27c7d10
[2011/05/10 19:29:10.113613, 10, pid=3540] lib/dbwrap_tdb.c:42(db_tdb_record_destr)
Unlocking key D40D0000FFFFFFFFFFFF
[2011/05/10 19:29:10.113754, 3, pid=3540] smbd/server.c:902(exit_server_common)
Server exit (failed to receive smb request)